All of lore.kernel.org
 help / color / mirror / Atom feed
* [OE-core][scarthgap 00/31] Patch review
@ 2026-07-26  8:29 Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19 Yoann Congal
                   ` (30 more replies)
  0 siblings, 31 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Tuesday, July 28.

Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/4287

The following changes since commit 3217490cc554069ae53aa54cf8ad7327ce85fa10:

  glibc-testsuite: Do not generate SPDX (2026-07-21 20:32:51 +0200)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

for you to fetch changes up to 762321beb0260b1411c7f98f13458ec99a118280:

  bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang (2026-07-25 23:57:45 +0200)

----------------------------------------------------------------

Bruce Ashfield (2):
  linux-yocto/6.6: update to v6.6.143
  linux-yocto/6.6: update to v6.6.144

Darsh Kelaiya (1):
  gzip: Fix CVE-2026-41991

Deepak Rathore (13):
  cups: fix CVE-2026-27447
  cups: fix CVE-2026-41079
  cups: fix CVE-2026-34978
  cups: fix CVE-2026-34980
  cups: fix CVE-2026-34979
  cups: fix CVE-2026-34990
  cups: fix CVE-2026-39314
  cups: fix CVE-2026-39316
  glib-2.0: fix CVE-2026-58010
  glib-2.0: fix CVE-2026-58011
  glib-2.0: fix CVE-2026-58012
  glib-2.0: fix CVE-2026-58013
  glib-2.0: fix CVE-2026-58014

Devansh Patel (8):
  libxml2: Fix CVE-2026-11979
  openssh: Fix CVE-2026-59999
  openssh: Fix CVE-2026-59997
  openssh: Fix CVE-2026-59996
  openssh: Fix CVE-2026-59995
  openssh: Fix CVE-2026-60001
  openssh: Fix CVE-2026-60002
  openssh: Fix CVE-2026-60000

Enoch Ng (1):
  libxpm: fix CVE-2026-4367

Hongxu Jia (1):
  bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang

Sudhir Dumbhare (3):
  gnutls: set status for CVE-2026-3832
  gnutls: fix CVE-2026-42009
  libpng: Fix CVE-2026-34757

Yoann Congal (2):
  scripts/install-buildtools: Update to 5.0.19
  linux-yocto/6.6: update CVE exclusions (6.6.144)

 .../openssh/openssh/CVE-2026-59995.patch      |   42 +
 .../openssh/openssh/CVE-2026-59996.patch      |   37 +
 .../openssh/openssh/CVE-2026-59997.patch      |   58 +
 .../openssh/openssh/CVE-2026-59999.patch      |   36 +
 .../openssh/openssh/CVE-2026-60000.patch      |  140 ++
 .../openssh/openssh/CVE-2026-60001.patch      |  130 ++
 .../openssh/openssh/CVE-2026-60002.patch      |  226 +++
 .../openssh/openssh_9.6p1.bb                  |    7 +
 .../glib-2.0/glib-2.0/CVE-2026-58010.patch    |  113 ++
 .../glib-2.0/glib-2.0/CVE-2026-58011.patch    |   78 ++
 .../glib-2.0/glib-2.0/CVE-2026-58012.patch    |  228 ++++
 .../glib-2.0/glib-2.0/CVE-2026-58013.patch    |  140 ++
 .../glib-2.0/glib-2.0/CVE-2026-58014.patch    |  106 ++
 meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |    5 +
 .../libxml/libxml2/CVE-2026-11979.patch       |   70 +
 meta/recipes-core/libxml/libxml2_2.12.10.bb   |    1 +
 ...-fix-bzip2-version-tmp-aaa-will-hang.patch |   65 +
 meta/recipes-extended/bzip2/bzip2_1.0.8.bb    |    1 +
 meta/recipes-extended/cups/cups.inc           |   12 +
 .../cups/CVE-2026-27447-regression_p1.patch   |   33 +
 .../cups/CVE-2026-27447-regression_p2.patch   |   46 +
 .../cups/cups/CVE-2026-27447.patch            |  108 ++
 .../cups/cups/CVE-2026-34978.patch            |  107 ++
 .../cups/cups/CVE-2026-34979.patch            |   61 +
 .../cups/CVE-2026-34980-regression_p1.patch   |   31 +
 .../cups/CVE-2026-34980-regression_p2.patch   |   75 +
 .../cups/cups/CVE-2026-34980.patch            |   85 ++
 .../cups/cups/CVE-2026-34990.patch            |  351 +++++
 .../cups/cups/CVE-2026-39314.patch            |   45 +
 .../cups/cups/CVE-2026-39316.patch            |   40 +
 .../cups/cups/CVE-2026-41079.patch            |   71 +
 .../gzip/gzip-1.13/CVE-2026-41991.patch       |   75 +
 meta/recipes-extended/gzip/gzip_1.13.bb       |    1 +
 ...67-Out-of-bounds-read-in-xpmNextWord.patch |  140 ++
 .../xorg-lib/libxpm_3.5.17.bb                 |    1 +
 .../linux/cve-exclusion_6.6.inc               | 1216 ++++++++++++++---
 .../linux/linux-yocto-rt_6.6.bb               |    6 +-
 .../linux/linux-yocto-tiny_6.6.bb             |    6 +-
 meta/recipes-kernel/linux/linux-yocto_6.6.bb  |   28 +-
 .../libpng/files/CVE-2026-34757_p1.patch      |  521 +++++++
 .../libpng/files/CVE-2026-34757_p2.patch      |  484 +++++++
 .../libpng/libpng_1.6.42.bb                   |    4 +-
 .../gnutls/gnutls/CVE-2026-42009_p1.patch     |   66 +
 .../gnutls/gnutls/CVE-2026-42009_p2.patch     |   47 +
 meta/recipes-support/gnutls/gnutls_3.8.4.bb   |    4 +
 scripts/install-buildtools                    |    4 +-
 46 files changed, 4964 insertions(+), 187 deletions(-)
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
 create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
 create mode 100644 meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34978.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34979.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34990.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39314.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39316.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-41079.patch
 create mode 100644 meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch
 create mode 100644 meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch
 create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
 create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch



^ permalink raw reply	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 02/31] linux-yocto/6.6: update to v6.6.143 Yoann Congal
                   ` (29 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Yoann Congal <yoann.congal@smile.fr>

Update to the 5.0.19 release of the 5.0 series for buildtools

Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 scripts/install-buildtools | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/scripts/install-buildtools b/scripts/install-buildtools
index 24cb3099453..65200e0cf49 100755
--- a/scripts/install-buildtools
+++ b/scripts/install-buildtools
@@ -57,8 +57,8 @@ logger = scriptutils.logger_create(PROGNAME, stream=sys.stdout)
 
 DEFAULT_INSTALL_DIR = os.path.join(os.path.split(scripts_path)[0],'buildtools')
 DEFAULT_BASE_URL = 'https://downloads.yoctoproject.org/releases/yocto'
-DEFAULT_RELEASE = 'yocto-5.0.18'
-DEFAULT_INSTALLER_VERSION = '5.0.18'
+DEFAULT_RELEASE = 'yocto-5.0.19'
+DEFAULT_INSTALLER_VERSION = '5.0.19'
 DEFAULT_BUILDDATE = '202110XX'
 
 # Python version sanity check


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 02/31] linux-yocto/6.6: update to v6.6.143
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 03/31] linux-yocto/6.6: update to v6.6.144 Yoann Congal
                   ` (28 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Bruce Ashfield <bruce.ashfield@gmail.com>

Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    d1cfde2d5d15 Linux 6.6.143
    726abf975668 netfilter: require Ethernet MAC header before using eth_hdr()
    05bd072e97fe x86/CPU/AMD: Rename init_amd_zn() to init_amd_zen_common()
    4a83b435acf8 x86/CPU/AMD: Call the spectral chicken in the Zen2 init function
    5e0c93dca433 x86/CPU/AMD: Move the Zen3 BTC_NO detection to the Zen3 init function
    217f53b5e3c6 Revert "selftest/ptp: update ptp selftest to exercise the gettimex options"
    189c7e57826f mptcp: fix missing wakeups in edge scenarios
    c12e67a0ef93 mptcp: add-addr: always drop other suboptions
    1111ab94fd49 arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
    e5b6bdc3d8b8 arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU
    e717a4d08779 arm64: errata: Mitigate TLBI errata on various Arm CPUs
    baf63e6a6435 arm64: cputype: Add C1-Premium definitions
    1e4a5225b4d3 arm64: cputype: Add C1-Ultra definitions
    f58e88f8653f arm64: cputype: Add NVIDIA Olympus definitions
    2602d4b53925 ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6
    9aa7edc1347b ipvs: skip ipv6 extension headers for csum checks
    2de5c8eea0a9 net: bonding: fix use-after-free in bond_xmit_broadcast()
    8fe0231adebe RDMA/umem: Fix truncation for block sizes >= 4G
    3faebd387ed1 RDMA: Move DMA block iterator logic into dedicated files
    a7c6be320c0e RDMA/umem: fix kernel-doc warnings
    09dc18894148 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
    09b8a7aa5a34 hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
    77b73b54801a mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
    252bb328b36f mm/memory-failure: fix missing ->mf_stats count in hugetlb poison
    05f1ad6d62a3 mm/hugetlb: rename folio_putback_active_hugetlb() to folio_putback_hugetlb()
    471f5d78ea4b mm/migrate: don't call folio_putback_active_hugetlb() on dst hugetlb folio
    411fa5113da0 mm/hugetlb: rename isolate_hugetlb() to folio_isolate_hugetlb()
    eb8a8124484d netfilter: nft_fib: fix stale stack leak via the OIFNAME register
    46582b0fd381 usb: typec: ucsi: Don't update power_supply on power role change if not connected
    c91ea13375f7 serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ
    d3e9b79aa794 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
    b4621e5ef634 thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
    078c11224c7f usb: typec: ucsi: Check if power role change actually happened before handling
    e15c414092b3 usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind
    5542d2c35930 usb: dwc3: xilinx: fix error handling in zynqmp init error paths
    b987f380620b usb: musb: omap2430: Fix use-after-free in omap2430_probe()
    a9c22e0f93ba tty: serial: samsung: Remove redundant port lock acquisition in rx helpers
    8809b7941c4a tty: serial: samsung: use u32 for register interactions
    33da47d4a003 serial: samsung_tty: Use port lock wrappers
    1cdb07d8946c ALSA: firewire-motu: Protect register DSP event queue positions
    b3f4f82d1315 memfd: deny writeable mappings when implying SEAL_WRITE
    2619d9d2aac3 iio: dac: ad5686: fix ref bit initialization for single-channel parts
    f8dcef820161 usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure
    e85bc501947f iio: chemical: scd30: fix division by zero in write_raw
    73d8bf36f217 iio: chemical: scd30: Use guard(mutex) to allow early returns
    86298fb6829c iio: gyro: adis16260: fix division by zero in write_raw
    b35e71b7cc7a mptcp: handle first subflow closing consistently
    792fa6eee73e Bluetooth: hci_qca: Convert timeout from jiffies to ms
    c3fc351d256c Bluetooth: hci_qca: Migrate to serdev specific shutdown function
    123724bb6ee5 serdev: Provide a bustype shutdown function
    ca2f48b9c03d serdev: make serdev_bus_type const
    c0e37017a452 mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()
    e7af1b15c884 mm/memory: fix spurious warning when unmapping device-private/exclusive pages
    fe76413677e7 mptcp: do not drop partial packets
    293b0e63136b mptcp: introduce the mptcp_init_skb helper
    681d14ef45b1 iio: adc: npcm: fix unbalanced clk_disable_unprepare()
    4ed1366f9f90 iio: adc: npcm: Convert to platform remove callback returning void
    d766a49d9b55 arm64: tlb: Flush walk cache when unsharing PMD tables
    4c29603498b0 octeontx2-pf: avoid double free of pool->stack on AQ init failure
    26342087fac9 af_unix: Fix UAF read of tail->len in unix_stream_data_wait()
    db9389042db4 af_unix: Cache state->msg in unix_stream_read_generic().
    c2c764b00c0f rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer
    a05bf6d9e621 rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg
    7713f4aafb57 net: hsr: defer node table free until after RCU readers
    1dca7e491f07 ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()
    dcc42d701529 ipv6/addrconf: annotate data-races around devconf fields (II)
    ada8dcfd5298 mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient
    04318e252c58 ice: fix VF queue configuration with low MTU values
    d37a60086ee7 selftests: mptcp: drop nanoseconds width specifier
    00ffe9893f4b mptcp: reset rcv wnd on disconnect
    1521fecf44fc mptcp: cleanup fallback dummy mapping generation
    78f9d747f386 mptcp: use plain bool instead of custom binary enum
    e043017ac429 octeontx2-af: CGX: add bounds check to cgx_speed_mbps index
    1132ca7a1ba8 octeontx2-af: replace deprecated strncpy with strscpy
    557edaf01062 platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery
    969bc6370334 smb: client: require net admin for CIFS SWN netlink
    e19eff331240 genetlink: Use internal flags for multicast groups
    14897ef9341c cgroup/cpuset: Reset DL migration state on can_attach() failure
    850452af77f5 ksmbd: fix OOB write in QUERY_INFO for compound requests
    6d8f52f3f80a fbdev/vt8500lcdfb: Initialize fb_ops with fbdev macros
    666bd0598f37 ipmi:ssif: NULL thread on error
    318a0403b270 ipmi:ssif: Remove unnecessary indention
    ae9d4caf6f13 mm/huge_memory: update file PMD counter before folio_put()
    310a8cc74612 soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
    428a33573dcb mm/hugetlb: avoid false positive lockdep assertion
    000e8f55fbc7 driver core: reject devices with unregistered buses
    b5fa9e32fb67 fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
    201151e120f0 drm/amd/display: Use krealloc_array() in dal_vector_reserve()
    7fc4fab4acc3 drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
    4d1c3c26c2ab drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
    79e0273272a0 drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
    3fe2c6af3f51 drm/amdgpu: restart the CS if some parts of the VM are still invalidated
    16dad1fb0d78 drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
    62bd09e23a23 drm/amdkfd: fix NULL dereference in get_queue_ids()
    d54a221b0f3c slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock
    9f4a76c7e9fa slimbus: qcom-ngd-ctrl: fix OF node refcount
    fc261397295b thunderbolt: Limit XDomain response copy to actual frame size
    0dd61ba03d05 thunderbolt: Validate XDomain request packet size before type cast
    5db10c8ad8c0 thunderbolt: Clamp XDomain response data copy to allocation size
    4d0b1524caad thunderbolt: Bound root directory content to block size
    5f56bc6bddff thunderbolt: Reject zero-length property entries in validator
    7dd9a42b044a sctp: stream: fully roll back denied add-stream state
    e97c2a535e23 sctp: diag: reject stale associations in dump_one path
    7e60d675288d mmc: sdhci: add signal voltage switch in sdhci_resume_host
    b46521877611 mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
    6dc14b9b431e mmc: litex_mmc: Set mandatory idle clocks before CMD0
    30e727657185 mmc: core: Fix host controller programming for fixed driver type
    8d6e1dd3ad13 mm/hugetlb: restore reservation on error in hugetlb folio copy paths
    f0ca9c7f44a9 octeontx2-af: fix memory leak in rvu_setup_hw_resources()
    033d498b0f47 nvmem: layouts: onie-tlv: fix hang on unknown types
    e7cf30aa5f1f net: rds: clear i_sends on setup unwind
    1ccad3ee7998 net: mv643xx: fix OF node refcount
    a629418d463f net: bonding: fix NULL pointer dereference in bond_do_ioctl()
    c090df5be6bc net/mlx5: Reorder completion before putting command entry in cmd_work_handler
    8fb4a23df5b7 misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
    d3e26df2e8eb misc: fastrpc: fix DMA address corruption due to find_vma misuse
    8b080c891831 misc: fastrpc: fix use-after-free race in fastrpc_map_create
    df08fadcf0e5 misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
    6560be3f6a5b ipc/shm: serialize orphan cleanup with shm_nattch updates
    7a395a147f06 Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
    81d60181ed55 Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
    2d175d6aae9c i2c: tegra: Fix NOIRQ suspend/resume
    5bebff5e8492 i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
    7107627b8b35 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
    dd92773d4d9c fuse: reject fuse_notify() pagecache ops on directories
    254c469a404a pidfd: refuse access to tasks that have started exiting harder
    0e823ca0e739 inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
    c1234229399f IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
    1a418ad0e5e5 bnxt_en: Fix NULL pointer dereference
    6f5285a6054a ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
    dfd853197615 vsock/vmci: fix sk_ack_backlog leak on failed handshake
    688fcac7054a wifi: nl80211: reject oversized EMA RNR lists
    eb13ab2f66e2 selftests: mptcp: add test for extra_subflows underflow on userspace PM
    026c4a70e2a9 mptcp: sockopt: check timestamping ret value
    b1fd13074f22 mptcp: allow subflow rcv wnd to shrink
    907ac6b1658e mptcp: close TOCTOU race while computing rcv_wnd
    f2c9012fc115 mptcp: fix retransmission loop when csum is enabled
    c2e3aadc8fef ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
    b6290cc96dc8 ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O
    c35c0763af34 ARM: socfpga: Fix OF node refcount leak in SMP setup
    1b585673a224 udp: clear skb->dev before running a sockmap verdict
    0c2821665ff7 zram: fix use-after-free in zram_bvec_write_partial()
    0d64bc200ebe RDMA/srp: bound SRP_RSP sense copy by the received length
    5c97ae9382de mm/damon/ops-common: call folio_test_lru() after folio_get()
    5242b5f3c77f drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info()
    898bd0ccfed7 drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
    e2331730175f ALSA: timer: Fix UAF at snd_timer_user_params()
    a1288cd700f7 USB: serial: kl5kusb105: fix bulk-out buffer overflow
    f71f8f99a9cd USB: serial: option: add usb-id for Dell Wireless DW5826e-m
    4cb722747ed2 USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
    d92f17af7097 USB: serial: io_ti: fix heap overflow in get_manuf_info()
    aa82a078f70f xfrm: espintcp: do not reuse an in-progress partial send
    0da2e073f9cb ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
    07c33be968d9 drm/i915/gem: Fix phys BO pread/pwrite with offset
    033d39e41fc3 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
    88520b2fecc4 mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
    1e927a468500 tracing/probes: Point the error offset correctly for eprobe argument error
    214a2042b16b Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
    1338ee049a89 Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
    8767fe4079af netfilter: nft_tunnel: fix use-after-free on object destroy
    e0ce103e89d6 drm/vc4: fix krealloc() memory leak
    ed3e134700a2 drm/virtio: Fix driver removal with disabled KMS
    c5f438dd2fd8 clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time
    5e1c1d22268a netfilter: ctnetlink: ensure safe access to master conntrack
    5f82b02b4059 ipv6: Fix a potential NPD in cleanup_prefix_route()
    ccdd7f1949bb net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
    580f92f27cb8 net: mvpp2: refill RX buffers before XDP or skb use
    26c0986cb613 net: mvpp2: Add metadata support for xdp mode
    3b8b0c3631b1 net: mvpp2: limit XDP frame size to the RX buffer
    bede0f481b91 net: mvpp2: sync RX data at the hardware packet offset
    cd513e43b4b2 netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
    8a81e336da68 netfilter: nf_log: validate MAC header was set before dumping it
    a0d16941adf3 netfilter: x_tables: avoid leaking percpu counter pointers
    29d8cc44bbdf netfilter: nf_conntrack: destroy stale expectfn expectations on unregister
    eb7e77342e3e rds: mark snapshot pages dirty in rds_info_getsockopt()
    f513f308cc4b ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
    0f22412a2f4f net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
    b903e9b5629e net: guard timestamp cmsgs to real error queue skbs
    8ce96f118264 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
    22f4ee66614e r8152: handle the return value of usb_reset_device()
    25fdf5369853 net: openvswitch: fix possible kfree_skb of ERR_PTR
    0bfa7bba1f41 ipv6: sit: reload inner IPv6 header after GSO offloads
    41781f278930 net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
    2047c2aa0963 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
    12fb84dc4dc8 net: phy: clean the sfp upstream if phy probing fails
    838f411b8ef8 net/mlx4: avoid GCC 10 __bad_copy_from() false positive
    ecfe9171b26a tcp: restrict SO_ATTACH_FILTER to priv users
    10def23b67b4 ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
    7db09011ce62 gpio: mvebu: fix NULL pointer dereference in suspend/resume
    07a18f5c90dd netlabel: validate unlabeled address and mask attribute lengths
    42827d03f800 xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
    f4e4b98cee82 iomap: don't revert iov_iter on partially completed buffered writes
    fed65bc9de8e arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI
    b7d3add1884c arm64: tlb: Allow XZR argument to TLBI ops
    523bc49979b9 KVM: arm64: Remove VPIPT I-cache handling
    d30aac0fa00c tap: free page on error paths in tap_get_user_xdp()
    ceafb893b12f net: skbuff: fix missing zerocopy reference in pskb_carve helpers
    9eaa4e8d5561 tools/rv: Fix cleanup after failed trace setup
    7fce959e9be3 usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo
    36c41e9724c9 usb: gadget: f_ncm: Fix net_device lifecycle with device_move
    d68b621bb5a4 ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
    c12c4cae0cd7 time: Fix off-by-one in settimeofday() usec validation
    f4aae11abb44 signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
    6e39863cefe4 ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp
    2afc9e684dc7 sctp: purge outqueue on stale COOKIE-ECHO handling
    6d6e42e8e17f net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
    1a827b95e62b ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()
    9db4dd019a6b vxlan: vnifilter: fix spurious notification on VNI update
    5a7ad529fd53 vxlan: vnifilter: send notification on VNI add
    e4e7428349d9 octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
    72775977e89c net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
    cecdc6574a82 ptp: vclock: Switch from RCU to SRCU
    8ff85dbabbbf ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
    ba760c38b38b Bluetooth: MGMT: Fix backward compatibility with userspace
    0622e527a31d Bluetooth: fix memory leak in error path of hci_alloc_dev()
    691f14b6a48b Bluetooth: bnep: reject short frames before parsing
    10e90715e68f Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling
    98377e6b1a1a Bluetooth: RFCOMM: validate skb length in MCC handlers
    74c08e4db35a Bluetooth: MGMT: validate advertising TLV before type checks
    de31973ef00e Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
    28a6a3762796 net: fec: fix pinctrl default state restore order on resume
    caeb42f28f00 net: lan743x: permit VLAN-tagged packets up to configured MTU
    74e02121be1d net: garp: fix unsigned integer underflow in garp_pdu_parse_attr
    271355c2ef61 hsr: Remove WARN_ONCE() in hsr_addr_is_self().
    91cdbb9b308f net: Annotate sk->sk_write_space() for UDP SOCKMAP.
    daf5a9eef894 pcnet32: stop holding device spin lock during napi_complete_done
    e732c4444bcf drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
    06ce6fc106b1 6lowpan: fix off-by-one in multicast context address compression
    8b136f18ac4b net/sched: act_api: use RCU with deferred freeing for action lifecycle
    b4892561552d dm cache policy smq: check allocation under invalidate lock
    afd64b59c3de netfilter: bridge: make ebt_snat ARP rewrite writable
    af80f78ce984 netfilter: nft_ct: bail out on template ct in get eval
    7c34f9130529 netfilter: conntrack_irc: fix possible out-of-bounds read
    0f8ba5e4c53d netfilter: synproxy: add mutex to guard hook reference counting
    c6376b9b1b4d ipvs: clear the svc scheduler ptr early on edit
    8122abd4fd92 netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
    945a86b21b40 ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers
    9a0dc9279d09 tee: optee: prevent use-after-free when the client exits before the supplicant
    5d27d2ffe487 net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
    2a613bf49702 ipv6: mcast: Fix use-after-free when processing MLD queries
    aa6ef7340169 i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
    067579d5cf8c Disable -Wattribute-alias for clang-23 and newer
    b26849cffaa7 hwmon: (pmbus/core) Protect regulator operations with mutex
    d859e53596d1 RDMA/rxe: Fix "trying to register non-static key in rxe_qp_do_cleanup" bug
    7502c1cf303b Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync
    90dbad14b109 USB: serial: mct_u232: fix memory corruption with small endpoint
    f8b8f1d4bb76 bpf: Free reuseport cBPF prog after RCU grace period.
    37f488be2a82 usb: core: Fix SuperSpeed root hub wMaxPacketSize
    ff3c2b623bfa HID: core: Fix size_t specifier in hid_report_raw_event()
    9e36568e67f8 HID: pass the buffer size to hid_report_raw_event
    20a816422e98 HID: core: Add printk_ratelimited variants to hid_warn() etc
    bb2040484f90 serial: zs: Convert to use a platform device
    c9e78361fe92 serial: dz: Convert to use a platform device
    5fc2943ad6a1 serial: dz: Fix bootconsole handover lockup
    bef9e8bdbc60 xhci: tegra: Fix ghost USB device on dual-role port unplug
    8a65db5edd7b USB: serial: digi_acceleport: fix memory corruption with small endpoints
    fbf718d5afe2 landlock: Fix handling of disconnected directories
    0e96cd314c0d x86/kexec: Disable KCOV instrumentation after load_segments()
    a55618c0f4ce Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
    4bcaa59f403d USB: serial: cypress_m8: fix memory corruption with small endpoint
    36f07474f2b9 serial: zs: Switch to using channel reset
    633a33fe1a34 serial: zs: Fix bootconsole handover lockup
    6f22119afe53 serial: dz: Fix bootconsole message clobbering at chip reset
    a8bd09d3d843 drm/amdkfd: Check for pdd drm file first in CRIU restore path
    4e5f808b4541 drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
    6495cc09f7e6 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr
    c33322ef3ce5 serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma
    ea7bdbee9fc3 serial: zs: Fix swapped RI/DSR modem line transition counting
    4860f9821baf serial: sh-sci: fix memory region release in error path
    70982b7ac673 serial: qcom-geni: fix UART_RX_PAR_EN bit position
    3c29f8af029b serial: altera_jtaguart: handle uart_add_one_port() failures
    a1b9535768ed drm/amd/pm/si: Disregard vblank time when no displays are connected
    28b22dbaf407 drm/i915: Fix potential UAF in TTM object purge
    049a6b474823 drm/hyperv: validate VMBus packet size in receive callback
    1fb565b77b8f drm/hyperv: validate resolution_count and fix WIN8 fallback
    edd06675a023 scsi: target: iscsi: Validate CHAP_R length before base64 decode
    4e9f0c4a645c scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
    163bd704d751 scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
    0e3c6e5a8fc1 scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker
    5506c825f14d thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow
    8d4a758b407a thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()
    e835bf9a055f usb: gadget: f_fs: copy only received bytes on short ep0 read
    a183b47fee46 usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports
    046870ff6b6f usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling
    5d39924ae38c usb: gadget: f_hid: fix device reference leak in hidg_alloc()
    085652fda7f3 usb: gadget: net2280: Fix double free in probe error path
    70bb9a2661d3 USB: serial: mct_u232: fix missing interrupt-in transfer sanity check
    be3a1ed4ae51 USB: serial: mxuport: fix memory corruption with small endpoint
    0bde5431037a USB: serial: keyspan: fix missing indat transfer sanity check
    be50533fe706 USB: serial: cypress_m8: validate interrupt packet headers
    ffb739a49186 USB: serial: belkin_sa: validate interrupt status length
    37a2ac9f5125 USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL
    5a0e65d56ffd USB: serial: option: add MeiG SRM813Q
    17587492179c usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize
    5de7df75ef3a usb: usbtmc: check URB actual_length for interrupt-IN notifications
    a0638db2340e usbip: vudc: Fix use after free bug in vudc_remove due to race condition
    02c76e026c06 usb: storage: Add quirks for PNY Elite Portable SSD
    aec4d38ac605 USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers
    e21f5abf80ad usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval
    028cc2555eca usb: chipidea: core: convert ci_role_switch to local variable
    6dd5c0ea139b tty: serial: pch_uart: add check for dma_alloc_coherent()
    68f603bb8622 counter: Fix refcount leak in counter_alloc() error path
    9fa854ea4318 comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest()
    422af0f9ce0c comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest()
    2ad3397f3cc5 Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490
    e9b62996ba53 Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
    0fe08c5776a7 ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops
    ba451cf21f1d Input: xpad - add support for ASUS ROG RAIKIRI II
    6e6de3eba8e4 Input: xpad - add "Nova 2 Lite" from GameSir
    322e48187e02 xfrm: esp: restore combined single-frag length gate
    d780c61bd2ef ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks
    ed4e2ff1ddd1 ASoC: qcom: q6asm-dai: close stream only when running
    2bb6d82b586e netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
    32aa292fbcb9 xfrm: ah: use skb_to_full_sk in async output callbacks
    00f2c451e57d xfrm: route MIGRATE notifications to caller's netns
    c4cc6b3b0013 nfc: hci: fix out-of-bounds read in HCP header parsing
    1552b979a0b6 iommu, debugobjects: avoid gcc-16.1 section mismatch warnings
    ed598de9f615 HID: wacom: Fix OOB write in wacom_hid_set_device_mode()
    f1e89a943ee5 ip6: vti: Use ip6_tnl.net in vti6_changelink().
    48ce101cd630 xfrm: input: hold netns during deferred transport reinjection
    a29768d56eb3 ipv6: validate extension header length before copying to cmsg
    1acfb7d9c6fc ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().
    12d957979e4a ipv6: exthdrs: refresh nh after handling HAO option
    f21a9285147a ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params
    bddaa4dfc7f3 ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
    679e13a65e68 macsec: fix replay protection at XPN lower-PN wrap
    96b72672ce84 bpf: sockmap: fix tail fragment offset in bpf_msg_push_data
    48b0aa9c08a3 Input: elan_i2c - validate firmware size before use
    0584af4fe40f usb: dwc2: Fix use after free in debug code
    c28bfafa9d70 usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles
    96291794d162 usb: cdns3: gadget: fix request skipping after clearing halt
    9a3860454bdf USB: serial: omninet: fix memory corruption with small endpoint
    29783e6b6ec0 iio: buffer: hw-consumer: fix use-after-free in error path
    d291f76e4231 iio: light: cm3323: fix reg_conf not being initialized correctly
    d534936cf3ac iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL
    c43741113cd6 iio: temperature: tsys01: fix broken PROM checksum validation
    b5d9befff543 iio: ssp_sensors: cancel delayed work_refresh on remove
    31bbd4b87dd6 iio: gyro: itg3200: fix i2c read into the wrong stack location
    d434a6abd101 iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw
    1c375f2c4a7a iio: dac: ad5686: acquire lock when doing powerdown control
    99d8feee7560 iio: dac: ad5686: fix input raw value check
    9a8fca2af3aa iio: dac: max5821: fix return value check in powerdown sync
    baff1f00d8b5 iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux
    7b9dcbe89d7a wireguard: send: append trailer after expanding head
    a452ca80b7ad KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC
    c881af73ae98 KVM: arm64: PMU: Preserve AArch32 counter low bits
    ecc9635e7501 USB: cdc-acm: Fix bit overlap and move quirk definitions to header
    15b1723c1472 parport: Fix race between port and client registration
    bcfb4833cd40 Input: xpad - fix out-of-bounds access for Share button
    35f68f36d988 Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock
    119fb6f80c44 Bluetooth: ISO: fix UAF in iso_recv_frame
    d313683d6ccd Bluetooth: HIDP: fix missing length checks in hidp_input_report()
    63cd225cc13d Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn
    89dec9204171 Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
    8776032fe989 auxdisplay: line-display: fix OOB read on zero-length message_store()
    157ce2c6836c ipc: limit next_id allocation to the valid ID range
    7c58c55a2a16 hpfs: fix a crash if hpfs_map_dnode_bitmap fails
    dcd2b02b095f Bluetooth: btusb: Allow firmware re-download when version matches
    4c52e31e9ea6 HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse
    0cd7b3a15a49 Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free()
    060fca8e0983 media: rc: igorplugusb: fix control request setup packet
    9b3145b3001f USB: serial: safe_serial: fix memory corruption with small endpoint
    156b6f0aec61 usb: typec: ucsi: validate connector number in ucsi_connector_change()
    0af00f1459f5 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
    5cd0e7ac4eef usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()
    70e7045849e9 usb: typec: altmodes/displayport: validate count before reading Status Update VDO
    592cbdc644c6 usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO
    3f432b820306 usb: typec: ucsi: ccg: reject firmware images without a ':' record header
    d42ac0bfb6a1 iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer
    d1c9c79eb06e soc/tegra: pmc: Fix unsafe generic_handle_irq() call
    0bb1522d3081 hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock
    96852c116071 hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock
    7e2476057950 x86/kexec: add a sanity check on previous kernel's ima kexec buffer
    566db3370f12 of/kexec: refactor ima_get_kexec_buffer() to use ima_validate_range()
    43308106a176 ima: verify the previous kernel's IMA buffer lies in addressable RAM
    e1d839efc1e4 phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X
    64858b76ec67 arm64: io: Extract user memory type in ioremap_prot()
    4356c4d85050 arm64: io: Rename ioremap_prot() to __ioremap_prot()
    05ff52238039 drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used
    45e27857b24e drm/dp: Add eDP 1.5 bit definition
    ac7045d3f6d3 drm/i915/psr: Read Intel DPCD workaround register
    28557e9deb23 drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register
    22ee4010866d inet: frags: flush pending skbs in fqdir_pre_exit()
    e0fc5427d6a8 inet: frags: add inet_frag_queue_flush()
    711ebd961190 drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup
    f707f53f9ff5 drm/fbdev-helper: Set and clear VGA switcheroo client from fb_info
    228cc232079d media: rc: ttusbir: fix inverted error logic
    a7becb58f6b8 media: rc: fix race between unregister and urb/irq callbacks
    3edb8ebbf79b mm/page_alloc: clear page->private in free_pages_prepare()
    a9393751ecf7 batman-adv: bla: avoid double decrement of bla.num_requests
    99f17d1cdb37 batman-adv: tt: avoid empty VLAN responses
    65a1e67339aa batman-adv: tt: fix TOCTOU race for reported vlans
    5bc2d50fb66b batman-adv: tp_meter: directly shut down timer on cleanup
    3c19cb8a84ef net: af_key: zero aligned sockaddr tail in PF_KEY exports
    100953b5011d batman-adv: tp_meter: avoid role confusion in tp_list
    cf12f8881832 batman-adv: iv: recover OGM scheduling after forward packet error
    13493b00dd1e batman-adv: tvlv: reject oversized TVLV packets
    2a8c9e865291 batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface
    a5904f2c92b0 batman-adv: tt: reject oversized local TVLV buffers
    fcedc98bd03c batman-adv: tvlv: abort OGM send on tvlv append failure
    31dcb9711abd batman-adv: v: stop OGMv2 on disabled interface
    ae1ada0af162 perf: Fix dangling cgroup pointer in cpuctx
    1488367423a6 net: skbuff: fix pskb_carve leaking zcopy pages
    c87cd3cb3096 ipv6: fix possible infinite loop in fib6_select_path()
    279853aec9f5 ipv6: fix possible infinite loop in rt6_fill_node()
    634a9af8a26a sctp: fix race between sctp_wait_for_connect and peeloff
    95e414f83243 net: mana: Add NULL guards in teardown path to prevent panic on attach failure
    88403b42faa8 gpio: rockchip: convert bank->clk to devm_clk_get_enabled()
    6319b38fe69f Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
    cc2b4f749de0 Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success
    97e06791368c ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
    65674d2489a1 ethtool: eeprom: add more safeties to EEPROM Netlink fallback
    091b58d9a65b ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback
    f4d78a81f57d bonding: refuse to enslave CAN devices
    b06203ac5f12 Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()
    5fe860af8630 ASoC: codecs: simple-mux: Fix enum control bounds check
    3127a884525d ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE
    e917d0c69f01 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
    dc3bfa050f87 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
    76cd9398a047 tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
    5165922a8b5c gpio: mxc: fix irq_high handling
    a4b64f3e9c7b net: hsr: fix potential OOB access in supervision frame handling
    e9e1dbdee16e ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors
    8e59d4d0dcde ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()
    15fb19af49f2 scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues
    cd691beafea0 net/iucv: fix locking in .getsockopt
    ed7a75831301 net/smc: Do not re-initialize smc hashtables
    e523bb6d1de3 net: netlink: don't set nsid on local notifications
    490a6ef32ab2 net: netlink: fix sending unassigned nsid after assigned one
    20f977a75333 vsock: keep poll shutdown state consistent
    60d9c0d6cdde tun: free page on build_skb failure in tun_xdp_one()
    5b34f9e4fe2f tun: free page on short-frame rejection in tun_xdp_one()
    b80ef316e978 netfilter: nf_tables: fix dst corruption in same register operation
    ce0712149e21 netfilter: bitwise: add support for doing AND, OR and XOR directly
    45cb4821021e netfilter: bitwise: rename some boolean operation functions
    a27cb7325a6c netfilter: ebtables: fix OOB read in compat_mtw_from_user
    21994d11461b netfilter: xt_cpu: prefer raw_smp_processor_id
    af2c22ccb1f6 netfilter: synproxy: refresh tcphdr after skb_ensure_writable
    d0cbeaa85b58 nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems
    fccd685b32df xfrm: Check for underflow in xfrm_state_mtu
    ee2d1a8a1833 nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
    e00f50f86977 nfc: llcp: Fix use-after-free in llcp_sock_release()
    67cca9df4d17 net: cpsw_new: Fix potential unregister of netdev that has not been registered yet
    4f33d74ccf69 bcache: fix uninitialized closure object
    b4a659bae3b8 drm: Remove plane hsub/vsub alignment requirement for core helpers
    6c153d97c100 net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked
    963537a26fd8 net: mctp: ensure our nlmsg responses are initialised
    5df49f0579f7 net/sched: cls_fw: fix NULL dereference of "old" filters before change()
    d883312061cc Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../linux/linux-yocto-rt_6.6.bb               |  6 ++--
 .../linux/linux-yocto-tiny_6.6.bb             |  6 ++--
 meta/recipes-kernel/linux/linux-yocto_6.6.bb  | 28 +++++++++----------
 3 files changed, 20 insertions(+), 20 deletions(-)

diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
index c3200cfd3fe..e5a3882efea 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
@@ -14,13 +14,13 @@ python () {
         raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
 }
 
-SRCREV_machine ?= "1ceada58731a98237f70384921758a4df3951960"
-SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98"
+SRCREV_machine ?= "fcddef60733f35eb43e4f8d5c7fd23d1c5bc4b24"
+SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
 
 SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
 
-LINUX_VERSION ?= "6.6.142"
+LINUX_VERSION ?= "6.6.143"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
index 563598a2bde..ed4b0c67ae7 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
@@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc
 # CVE exclusions
 include recipes-kernel/linux/cve-exclusion_6.6.inc
 
-LINUX_VERSION ?= "6.6.142"
+LINUX_VERSION ?= "6.6.143"
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
 DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native"
 KMETA = "kernel-meta"
 KCONF_BSP_AUDIT_LEVEL = "2"
 
-SRCREV_machine ?= "66e051144e21d531fa26ef67476dfdefbfc119a2"
-SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98"
+SRCREV_machine ?= "14b1b02cc139bf807405c9ad97a799a1dbfc0e4d"
+SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
 
 PV = "${LINUX_VERSION}+git"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
index 07a06f18529..c682d6ff17a 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
@@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base"
 KBRANCH:qemuloongarch64  ?= "v6.6/standard/base"
 KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64"
 
-SRCREV_machine:qemuarm ?= "d81ffd8843535762fecf5aa5fb2ca7d2c4343038"
-SRCREV_machine:qemuarm64 ?= "1f7f3a52dacadfcc75863f25252a534b06fdaeeb"
-SRCREV_machine:qemuloongarch64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemumips ?= "4410226fddf113b89cceb26e7ee5ca5bb70c55fb"
-SRCREV_machine:qemuppc ?= "8f8faf1fe9183f295901f8f2b8916ff54f4a4bfb"
-SRCREV_machine:qemuriscv64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemuriscv32 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemux86 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemux86-64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemumips64 ?= "14ca63e9f1ce2090e189c16b1024ed3df8f833f0"
-SRCREV_machine ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98"
+SRCREV_machine:qemuarm ?= "900d4f2a9c0cd33b2f32053ea438c709ca4fc69c"
+SRCREV_machine:qemuarm64 ?= "5f9c75b34f19ebfb1ac2cf26b0cdf1e637b0a67b"
+SRCREV_machine:qemuloongarch64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemumips ?= "d066c05c4207d69ff781175fbd4544af3a57a6e4"
+SRCREV_machine:qemuppc ?= "c9444b37f0f19f6f7186e4936f940b2e29cef806"
+SRCREV_machine:qemuriscv64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemuriscv32 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemux86 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemux86-64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemumips64 ?= "4c96d4f0d9ae5848015aa021c683bc1c68b596ee"
+SRCREV_machine ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
 
 # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
 # get the <version>/base branch, which is pure upstream -stable, and the same
 # meta SRCREV as the linux-yocto-standard builds. Select your version using the
 # normal PREFERRED_VERSION settings.
 BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "924b4a879cbb75aef37c160b955b92f6894b11a4"
+SRCREV_machine:class-devupstream ?= "d1cfde2d5d15be14123bdd1689162bd27f995a90"
 PN:class-devupstream = "linux-yocto-upstream"
 KBRANCH:class-devupstream = "v6.6/base"
 
@@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.6.142"
+LINUX_VERSION ?= "6.6.143"
 
 PV = "${LINUX_VERSION}+git"
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 03/31] linux-yocto/6.6: update to v6.6.144
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19 Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 02/31] linux-yocto/6.6: update to v6.6.143 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 04/31] linux-yocto/6.6: update CVE exclusions (6.6.144) Yoann Congal
                   ` (27 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Bruce Ashfield <bruce.ashfield@gmail.com>

Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    da47cbc254661 Linux 6.6.144
    6848a6e39cac4 crypto: qat - remove unused character device and IOCTLs
    1a42f84b0f6b5 crypto: qat - Return pointer directly in adf_ctl_alloc_resources
    30d648e225447 crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user()
    c0b8e6eea1b2b Documentation: ioctl-number: Extend "Include File" column width
    802e113cf120d drivers/base/memory: set mem->altmap after successful device registration
    511d2b92f8d20 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
    851e1847f881e serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
    36599894fa853 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
    2ef8f2a5695ae NFS: Prevent resource leak in nfs_alloc_server()
    6c344fff2feff NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
    abc978daffd26 nfsd: check get_user() return when reading princhashlen
    1e96239fddcef nfsd: fix posix_acl leak on SETACL decode failure
    1e04be34cafae NFSD: Fix SECINFO_NO_NAME decode error cleanup
    1a7ee9f9f3957 fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
    c7dc382439f7b fbdev: modedb: fix a possible UAF in fb_find_mode()
    7640b4f68acb5 fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
    c04d606f8b35e power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
    889c2a9c59897 KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
    d18756b12aab3 KVM: x86: hyper-v: Bound the bank index when querying sparse banks
    b84f46179c806 9p: avoid putting oldfid in p9_client_walk() error path
    c5a125eadba05 ocfs2: reject oversized group bitmap descriptors
    ddf13f91ca82c rpmsg: char: Fix use-after-free on probe error path
    fbaf509ad7cb2 fpga: region: fix use-after-free in child_regions_with_firmware()
    44567537a2623 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
    7e37e9b3e82ad pNFS: Fix use-after-free in pnfs_update_layout()
    eaca7dae02fab tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
    96e545410c4f7 blk-cgroup: fix UAF in __blkcg_rstat_flush()
    508a0139d3bf6 hdlc_ppp: sync per-proto timers before freeing hdlc state
    4fe388218826d gfs2: fix use-after-free in gfs2_qd_dealloc
    8e0abc17fbd7e exfat: fix potential use-after-free in exfat_find_dir_entry()
    ab465495b1ed5 MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
    81fc9a13acae9 bpf: use kvfree() for replaced sysctl write buffer
    fda128096fc84 f2fs: keep atomic write retry from zeroing original data
    7e4d8f98be63f f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
    1ddf3fd21c4c6 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
    24f8c87070c3e f2fs: fix to round down start offset of fallocate for pin file
    13e4b59d3a941 f2fs: validate compress cache inode only when enabled
    bd499f138ccf7 wifi: iwlwifi: mvm: fix race condition in PTP removal
    2b2060c2075a7 wifi: rtw88: usb: fix memory leaks on USB write failures
    6579dcb5e0f74 wifi: rtw88: increase TX report timeout to fix race condition
    16eef2a52687b wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
    318703b6f71d1 wifi: ath11k: fix warning when unbinding
    a2e631fa91bb2 wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
    35ab4db86774d keys: Pin request_key_auth payload in instantiate paths
    5966e4e2ba213 KEYS: fix overflow in keyctl_pkey_params_get_2()
    03ef56495f0be err.h: use __always_inline on all error pointer helpers
    5267eab88fa4c fbdev: fix use-after-free in store_modes()
    06f6dd2ff2bd0 NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
    15fd83a1e42ed apparmor: fix use-after-free in rawdata dedup loop
    faea60deaa05c apparmor: mediate the implicit connect of TCP fast open sendmsg
    0eb4c16c4adb2 net: skmsg: preserve sg.copy across SG transforms
    e28e7fd34c449 mac802154: llsec: add skb_cow_data() before in-place crypto
    82c17e13d404f af_unix: Set gc_in_progress to true in unix_gc().
    5f0b95ef68ab9 nvmet-tcp: fix race between ICReq handling and queue teardown
    e8852ae29868e ntfs3: reject direct userspace writes to reserved $LX* xattrs
    ce494707a9c07 ipv4: account for fraggap on the paged allocation path
    f79f0db614160 inet: add indirect call wrapper for getfrag() calls
    65fb14cbebb0c ipv6: account for fraggap on the paged allocation path
    2660bd8333ab6 batman-adv: tvlv: avoid race of cifsnotfound handler state
    9c9f4e69368a4 batman-adv: tvlv: enforce 2-byte alignment
    d7fdbab25eae6 batman-adv: dat: prevent false sharing between VLANs
    a8da361cdd929 batman-adv: tt: track roam count per VID
    e82a02a0c1aa2 batman-adv: tt: don't merge change entries with different VIDs
    0e868200cf042 batman-adv: tp_meter: handle overlapping packets
    31dec4dc86cf6 batman-adv: tp_meter: prevent parallel modifications of last_recv
    be3af0c705a13 batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
    f8c499fd275e5 batman-adv: tp_meter: restrict number of unacked list entries
    97644fdaaf644 batman-adv: v: prevent OGM aggregation on disabled hardif
    3af7f10d5fe44 batman-adv: frag: avoid underflow of TTL
    cb96aa1737200 batman-adv: frag: ensure fragment is writable before modifying TTL
    5263ff0bbd132 batman-adv: fix (m|b)cast csum after decrementing TTL
    4741001ca0b04 batman-adv: ensure bcast is writable before modifying TTL
    29f59324e61fc batman-adv: tp_meter: initialize last_recv_time during init
    b88f8f4e5e78e batman-adv: prevent ELP transmission interval underflow
    b5cf66cdc49b1 batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
    75445cf501ac7 batman-adv: tp_meter: add only finished tp_vars to lists
    4774a32baec46 batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
    ec8ef37fea33c batman-adv: tp_meter: fix fast recovery precondition
    cd74176cf1685 batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
    f58e5df92180e batman-adv: tp_meter: avoid window underflow
    774d22045a8fa batman-adv: tp_meter: initialize dec_cwnd explicitly
    0c610db91bbde batman-adv: tp_meter: initialize dup_acks explicitly
    edae04afb11f6 batman-adv: tp_meter: keep unacked list in ascending ordered
    bc6c380c1159d selinux: fix overlayfs mmap() and mprotect() access checks
    41c5b269af8b1 lsm: add backing_file LSM hooks
    ba3ebdd89fa20 fs: prepare for adding LSM blob to backing_file
    922a03b26e354 Bluetooth: btmtk: accept too short WMT FUNC_CTRL events
    36c85f7029484 Bluetooth: btmtk: validate WMT event SKB length before struct access
    7536ebe0473d9 Revert "ptp: add testptp mask test"
    48b91ed7e22bb KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
    9291654d69e08 KVM: x86: Fix shadow paging use-after-free due to unexpected role
    2de4db145b299 eventpoll: fix ep_remove struct eventpoll / struct file UAF
    a0e685da1efe0 eventpoll: move epi_fget() up
    20423e2c1c84a eventpoll: rename ep_remove_safe() back to ep_remove()
    0a4a2db528b0e eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}()
    f484ab90b2290 eventpoll: kill __ep_remove()
    903070f8f3552 eventpoll: split __ep_remove()
    ff4fe83a9aabb eventpoll: use hlist_is_singular_node() in __ep_remove()
    44e8907b81fea file: add fput() cleanup helper
    2181a09ba980f virtiofs: fix UAF on submount umount
    cd923dadefadb media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
    d2bbbb6c55812 ksmbd: reject non-VALID session in compound request branch
    8232fca738011 vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
    08fbcba06e968 scripts/sorttable: Fix endianness handling in build-time mcount sort
    80514e97c50ab scripts/sorttable: Allow matches to functions before function entry
    9ba53f9808e1e scripts/sorttable: Use normal sort if theres no relocs in the mcount section
    e115e9fa69b48 ftrace: Check against is_kernel_text() instead of kaslr_offset()
    379e755ec2c54 ftrace: Test mcount_loc addr before calling ftrace_call_addr()
    bf802b936a7b2 ftrace: Do not over-allocate ftrace memory
    4c30b173b6176 ftrace: Have ftrace pages output reflect freed pages
    dc06779d338de ftrace: Update the mcount_loc check of skipped entries
    4893af6318fe8 scripts/sorttable: Zero out weak functions in mcount_loc table
    bbfbacec9e000 scripts/sorttable: Always use an array for the mcount_loc sorting
    38be2ffe9808b scripts/sorttable: Have mcount rela sort use direct values
    fe0434d604a94 arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64
    8297f13962063 scripts/sorttable: Use a structure of function pointers for elf helpers
    ff7e015d63849 scripts/sorttable: Get start/stop_mcount_loc from ELF file directly
    ecbb09356560c scripts/sorttable: Move code from sorttable.h into sorttable.c
    7fbddce9a2685 scripts/sorttable: Use uint64_t for mcount sorting
    23b5a9659a27d scripts/sorttable: Add helper functions for Elf_Sym
    8cd6caaa4a244 scripts/sorttable: Add helper functions for Elf_Shdr
    a03240485cf57 scripts/sorttable: Add helper functions for Elf_Ehdr
    1dd7def1ae877 scripts/sorttable: Convert Elf_Sym MACRO over to a union
    1afca399cc4d5 scripts/sorttable: Replace Elf_Shdr Macro with a union
    7ce5ed40d976e scripts/sorttable: Convert Elf_Ehdr to union
    e6bb2482b5b17 scripts/sorttable: Make compare_extable() into two functions
    d5e14532a8b86 scripts/sorttable: Have the ORC code use the _r() functions to read
    4f2fba2de0620 scripts/sorttable: Remove unneeded Elf_Rel
    c13a4c1fd1b74 scripts/sorttable: Remove unused write functions
    d9e259e63b36b scripts/sorttable: Remove unused macro defines
    030fe3e9d8abd fuse: re-lock request before replacing page cache folio
    fe95e90559bce slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD
    e65ae7c948640 slimbus: qcom-ngd-ctrl: Fix up platform_driver registration
    5d1ae4e17a3ec rxrpc: Fix the ACK parser to extract the SACK table for parsing
    09c9b92c20104 net: phonet: free phonet_device after RCU grace period
    210ac54bdd8df phonet: Pass net and ifindex to phonet_address_notify().
    cf30797ea8cea phonet: Pass ifindex to fill_addr().
    6707d7e0b7174 locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
    67fde21e4522e Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
    5df8310a41391 hv: utils: handle and propagate errors in kvp_register
    23e5a1b9ae954 mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation
    4830fb44d12f5 netfilter: nf_tables: always walk all pending catchall elements
    7109d69bec6ed dlm: prevent NPD when writing a positive value to event_done
    c84860dac7af7 regulator: core: fix locking in regulator_resolve_supply() error path
    c2716362ec335 ring-buffer: Remove ring_buffer_read_prepare_sync()
    f155b8f1c9576 selftests/bpf: Update comments find_equal_scalars->sync_linked_regs
    8e655dbef4c9e selftests/bpf: Tests for per-insn sync_linked_regs() precision tracking
    78da8e1be90c5 bpf: Remove mark_precise_scalar_ids()
    0252b9d262222 bpf: Track equal scalars history on per-instruction level
    b741c9c6ef59f af_unix: Reject SIOCATMARK on non-stream sockets
    f68f34033d403 selftests/bpf: Add test to ensure kprobe_multi is not sleepable
    89327ed787746 bpf: Reject sleepable kprobe_multi programs at attach time
    eb045714bc6a2 agp/amd64: Fix broken error propagation in agp_amd64_probe()
    1078ae8175777 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
    1c4ffe6b4f043 i2c: stub: Reject I2C block transfers with invalid length
    c19b360fa10c5 RDMA/bnxt_re: zero shared page before exposing to userspace
    218c24bfc3334 KVM: VMX: Update SVI during runtime APICv activation
    de1ba6c93868f ARM: fix branch predictor hardening
    1f7cc85046f1c ARM: fix hash_name() fault
    98b209cd62ef9 ARM: allow __do_kernel_fault() to report execution of memory faults
    89b37df6f805f ARM: group is_permission_fault() with is_translation_fault()
    5d95f6b267f3d debugobjects: Dont call fill_pool() in early boot hardirq context
    a3383df76f0d7 debugobjects: Do not fill_pool() if pi_blocked_on
    c8cd2ca8f085c debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP
    0d2a64411b097 debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING
    40fe77146137b batman-adv: tt: prevent TVLV entry number overflow
    abb069fdf51a9 drm/v3d: Skip CSD when it has zeroed workgroups
    756724002c5a6 drm/v3d: Store the active job inside the queue's state
    f4b6b4af7ef06 ip6_vti: set netns_immutable on the fallback device.
    499c6b43a79dd drm/amd/display: Bound VBIOS record-chain walk loops
    b685d6ef6f07a net/sched: fix pedit partial COW leading to page cache corruption
    8bef2f840b43e fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../linux/linux-yocto-rt_6.6.bb               |  6 ++--
 .../linux/linux-yocto-tiny_6.6.bb             |  6 ++--
 meta/recipes-kernel/linux/linux-yocto_6.6.bb  | 28 +++++++++----------
 3 files changed, 20 insertions(+), 20 deletions(-)

diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
index e5a3882efea..cb8d8c418f1 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
@@ -14,13 +14,13 @@ python () {
         raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
 }
 
-SRCREV_machine ?= "fcddef60733f35eb43e4f8d5c7fd23d1c5bc4b24"
-SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
+SRCREV_machine ?= "d7fbdb4e5e7a35bdb8bb87d159204d74ef130a32"
+SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af"
 
 SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
 
-LINUX_VERSION ?= "6.6.143"
+LINUX_VERSION ?= "6.6.144"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
index ed4b0c67ae7..73d971f7eee 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
@@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc
 # CVE exclusions
 include recipes-kernel/linux/cve-exclusion_6.6.inc
 
-LINUX_VERSION ?= "6.6.143"
+LINUX_VERSION ?= "6.6.144"
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
 DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native"
 KMETA = "kernel-meta"
 KCONF_BSP_AUDIT_LEVEL = "2"
 
-SRCREV_machine ?= "14b1b02cc139bf807405c9ad97a799a1dbfc0e4d"
-SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
+SRCREV_machine ?= "25b07b85b558f3587c11c9363cccd9cb93fcef45"
+SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af"
 
 PV = "${LINUX_VERSION}+git"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
index c682d6ff17a..64609554ee2 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
@@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base"
 KBRANCH:qemuloongarch64  ?= "v6.6/standard/base"
 KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64"
 
-SRCREV_machine:qemuarm ?= "900d4f2a9c0cd33b2f32053ea438c709ca4fc69c"
-SRCREV_machine:qemuarm64 ?= "5f9c75b34f19ebfb1ac2cf26b0cdf1e637b0a67b"
-SRCREV_machine:qemuloongarch64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemumips ?= "d066c05c4207d69ff781175fbd4544af3a57a6e4"
-SRCREV_machine:qemuppc ?= "c9444b37f0f19f6f7186e4936f940b2e29cef806"
-SRCREV_machine:qemuriscv64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemuriscv32 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemux86 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemux86-64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemumips64 ?= "4c96d4f0d9ae5848015aa021c683bc1c68b596ee"
-SRCREV_machine ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
+SRCREV_machine:qemuarm ?= "3adc19c1e1e3ee865f9b0d7bc0fedd0e4aeee995"
+SRCREV_machine:qemuarm64 ?= "39a4fe09d3d795042cc14eb3c78f6a03874c48df"
+SRCREV_machine:qemuloongarch64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemumips ?= "ba0b8f925ec8b5926c6c2ddbc2c2c77305324bab"
+SRCREV_machine:qemuppc ?= "66c01b44545110249c940f865c4ed10d4d315b29"
+SRCREV_machine:qemuriscv64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemuriscv32 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemux86 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemux86-64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemumips64 ?= "1793417d6568e244579278e6f1fc7107987946f5"
+SRCREV_machine ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af"
 
 # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
 # get the <version>/base branch, which is pure upstream -stable, and the same
 # meta SRCREV as the linux-yocto-standard builds. Select your version using the
 # normal PREFERRED_VERSION settings.
 BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "d1cfde2d5d15be14123bdd1689162bd27f995a90"
+SRCREV_machine:class-devupstream ?= "da47cbc254661aa66d61ef061485a7080305c4be"
 PN:class-devupstream = "linux-yocto-upstream"
 KBRANCH:class-devupstream = "v6.6/base"
 
@@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.6.143"
+LINUX_VERSION ?= "6.6.144"
 
 PV = "${LINUX_VERSION}+git"
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 04/31] linux-yocto/6.6: update CVE exclusions (6.6.144)
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (2 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 03/31] linux-yocto/6.6: update to v6.6.144 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 05/31] libxml2: Fix CVE-2026-11979 Yoann Congal
                   ` (26 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Yoann Congal <yoann.congal@smile.fr>

$ ./meta/recipes-kernel/linux/generate-cve-exclusions.py .../cvelistV5/ 6.6.144 > meta/recipes-kernel/linux/cve-exclusion_6.6.inc

Generated at 2026-07-23 08:09:32.765073+00:00 for kernel version 6.6.144
From cvelistV5 cve_2026-07-23_0700Z

Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../linux/cve-exclusion_6.6.inc               | 1216 ++++++++++++++---
 1 file changed, 1052 insertions(+), 164 deletions(-)

diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc
index 2a194e7c84d..fd17e611a4b 100644
--- a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc
@@ -1,11 +1,11 @@
 
 # Auto-generated CVE metadata, DO NOT EDIT BY HAND.
-# Generated at 2026-07-07 17:39:10.952928+00:00 for kernel version 6.6.142
-# From cvelistV5 cve_2026-07-07_1600Z
+# Generated at 2026-07-23 08:09:32.765073+00:00 for kernel version 6.6.144
+# From cvelistV5 cve_2026-07-23_0700Z
 
 
 python check_kernel_cve_status_version() {
-    this_version = "6.6.142"
+    this_version = "6.6.144"
     kernel_version = d.getVar("LINUX_VERSION")
     if kernel_version != this_version:
         bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version))
@@ -15132,7 +15132,7 @@ CVE_STATUS[CVE-2024-58091] = "fixed-version: only affects 6.11 onwards"
 
 CVE_STATUS[CVE-2024-58092] = "fixed-version: only affects 6.8 onwards"
 
-# CVE-2024-58093 needs backporting (fixed from 6.15)
+CVE_STATUS[CVE-2024-58093] = "cpe-stable-backport: Backported in 6.6.87"
 
 # CVE-2024-58094 needs backporting (fixed from 6.15)
 
@@ -15520,7 +15520,7 @@ CVE_STATUS[CVE-2025-21815] = "fixed-version: only affects 6.7 onwards"
 
 CVE_STATUS[CVE-2025-21816] = "cpe-stable-backport: Backported in 6.6.93"
 
-CVE_STATUS[CVE-2025-21817] = "fixed-version: only affects 6.13.2 onwards"
+CVE_STATUS[CVE-2025-21817] = "fixed-version: only affects 6.12.96 onwards"
 
 CVE_STATUS[CVE-2025-21819] = "cpe-stable-backport: Backported in 6.6.78"
 
@@ -16142,7 +16142,7 @@ CVE_STATUS[CVE-2025-22128] = "fixed-version: only affects 6.8 onwards"
 
 # CVE-2025-23130 needs backporting (fixed from 6.15)
 
-# CVE-2025-23131 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2025-23131] = "cpe-stable-backport: Backported in 6.6.144"
 
 # CVE-2025-23132 needs backporting (fixed from 6.15)
 
@@ -19764,7 +19764,7 @@ CVE_STATUS[CVE-2025-68294] = "fixed-version: only affects 6.15 onwards"
 
 CVE_STATUS[CVE-2025-68295] = "cpe-stable-backport: Backported in 6.6.119"
 
-# CVE-2025-68296 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2025-68296] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2025-68297] = "cpe-stable-backport: Backported in 6.6.119"
 
@@ -19958,7 +19958,7 @@ CVE_STATUS[CVE-2025-68734] = "cpe-stable-backport: Backported in 6.6.117"
 
 CVE_STATUS[CVE-2025-68735] = "fixed-version: only affects 6.10 onwards"
 
-# CVE-2025-68736 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2025-68736] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2025-68737] = "fixed-version: only affects 6.18 onwards"
 
@@ -20022,7 +20022,7 @@ CVE_STATUS[CVE-2025-68766] = "cpe-stable-backport: Backported in 6.6.120"
 
 CVE_STATUS[CVE-2025-68767] = "cpe-stable-backport: Backported in 6.6.120"
 
-# CVE-2025-68768 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2025-68768] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2025-68769] = "cpe-stable-backport: Backported in 6.6.120"
 
@@ -21098,7 +21098,7 @@ CVE_STATUS[CVE-2026-23275] = "fixed-version: only affects 6.13 onwards"
 
 CVE_STATUS[CVE-2026-23277] = "cpe-stable-backport: Backported in 6.6.130"
 
-# CVE-2026-23278 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-23278] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-23279] = "cpe-stable-backport: Backported in 6.6.130"
 
@@ -21230,7 +21230,7 @@ CVE_STATUS[CVE-2026-23344] = "fixed-version: only affects 6.19 onwards"
 
 CVE_STATUS[CVE-2026-23345] = "fixed-version: only affects 6.13 onwards"
 
-# CVE-2026-23346 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-23346] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-23347] = "cpe-stable-backport: Backported in 6.6.130"
 
@@ -21546,7 +21546,7 @@ CVE_STATUS[CVE-2026-31417] = "cpe-stable-backport: Backported in 6.6.134"
 
 CVE_STATUS[CVE-2026-31418] = "cpe-stable-backport: Backported in 6.6.134"
 
-# CVE-2026-31419 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-31419] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-31420 needs backporting (fixed from 7.0)
 
@@ -21572,7 +21572,7 @@ CVE_STATUS[CVE-2026-31430] = "cpe-stable-backport: Backported in 6.6.135"
 
 CVE_STATUS[CVE-2026-31431] = "cpe-stable-backport: Backported in 6.6.137"
 
-# CVE-2026-31432 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-31432] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-31433] = "cpe-stable-backport: Backported in 6.6.131"
 
@@ -21680,7 +21680,7 @@ CVE_STATUS[CVE-2026-31484] = "fixed-version: only affects 6.19 onwards"
 
 CVE_STATUS[CVE-2026-31485] = "cpe-stable-backport: Backported in 6.6.131"
 
-# CVE-2026-31486 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-31486] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-31487 needs backporting (fixed from 7.0)
 
@@ -22294,7 +22294,7 @@ CVE_STATUS[CVE-2026-43008] = "fixed-version: only affects 6.19 onwards"
 
 # CVE-2026-43009 needs backporting (fixed from 7.0)
 
-# CVE-2026-43010 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-43010] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-43011] = "cpe-stable-backport: Backported in 6.6.134"
 
@@ -22312,7 +22312,7 @@ CVE_STATUS[CVE-2026-43017] = "cpe-stable-backport: Backported in 6.6.134"
 
 CVE_STATUS[CVE-2026-43018] = "cpe-stable-backport: Backported in 6.6.134"
 
-# CVE-2026-43019 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43019] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-43020] = "cpe-stable-backport: Backported in 6.6.134"
 
@@ -22450,7 +22450,7 @@ CVE_STATUS[CVE-2026-43086] = "cpe-stable-backport: Backported in 6.6.136"
 
 CVE_STATUS[CVE-2026-43087] = "fixed-version: only affects 6.19 onwards"
 
-# CVE-2026-43088 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43088] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-43089] = "cpe-stable-backport: Backported in 6.6.136"
 
@@ -22506,7 +22506,7 @@ CVE_STATUS[CVE-2026-43114] = "cpe-stable-backport: Backported in 6.6.136"
 
 # CVE-2026-43115 needs backporting (fixed from 7.0)
 
-# CVE-2026-43116 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43116] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-43117] = "cpe-stable-backport: Backported in 6.6.136"
 
@@ -22530,7 +22530,7 @@ CVE_STATUS[CVE-2026-43124] = "cpe-stable-backport: Backported in 6.6.128"
 
 CVE_STATUS[CVE-2026-43128] = "cpe-stable-backport: Backported in 6.6.128"
 
-# CVE-2026-43129 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43129] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-43130] = "cpe-stable-backport: Backported in 6.6.128"
 
@@ -22710,7 +22710,7 @@ CVE_STATUS[CVE-2026-43217] = "fixed-version: only affects 6.15 onwards"
 
 CVE_STATUS[CVE-2026-43218] = "cpe-stable-backport: Backported in 6.6.128"
 
-# CVE-2026-43219 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43219] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-43220] = "cpe-stable-backport: Backported in 6.6.140"
 
@@ -22752,7 +22752,7 @@ CVE_STATUS[CVE-2026-43238] = "cpe-stable-backport: Backported in 6.6.128"
 
 CVE_STATUS[CVE-2026-43239] = "cpe-stable-backport: Backported in 6.6.128"
 
-# CVE-2026-43240 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43240] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-43241] = "cpe-stable-backport: Backported in 6.6.128"
 
@@ -22878,7 +22878,7 @@ CVE_STATUS[CVE-2026-43301] = "fixed-version: only affects 6.8 onwards"
 
 CVE_STATUS[CVE-2026-43302] = "cpe-stable-backport: Backported in 6.6.128"
 
-# CVE-2026-43303 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43303] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-43304] = "cpe-stable-backport: Backported in 6.6.128"
 
@@ -22894,7 +22894,7 @@ CVE_STATUS[CVE-2026-43307] = "fixed-version: only affects 6.12 onwards"
 
 # CVE-2026-43310 needs backporting (fixed from 7.0)
 
-# CVE-2026-43311 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43311] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-43312] = "cpe-stable-backport: Backported in 6.6.128"
 
@@ -22934,7 +22934,7 @@ CVE_STATUS[CVE-2026-43329] = "cpe-stable-backport: Backported in 6.6.134"
 
 CVE_STATUS[CVE-2026-43330] = "cpe-stable-backport: Backported in 6.6.134"
 
-# CVE-2026-43331 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43331] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-43332] = "cpe-stable-backport: Backported in 6.6.134"
 
@@ -23114,7 +23114,7 @@ CVE_STATUS[CVE-2026-43419] = "cpe-stable-backport: Backported in 6.6.130"
 
 CVE_STATUS[CVE-2026-43420] = "cpe-stable-backport: Backported in 6.6.130"
 
-# CVE-2026-43421 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43421] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-43424] = "cpe-stable-backport: Backported in 6.6.130"
 
@@ -23308,7 +23308,7 @@ CVE_STATUS[CVE-2026-45848] = "cpe-stable-backport: Backported in 6.6.128"
 
 CVE_STATUS[CVE-2026-45849] = "cpe-stable-backport: Backported in 6.6.128"
 
-# CVE-2026-45850 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-45850] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-45851] = "cpe-stable-backport: Backported in 6.6.128"
 
@@ -23468,7 +23468,7 @@ CVE_STATUS[CVE-2026-45928] = "fixed-version: only affects 6.8 onwards"
 
 CVE_STATUS[CVE-2026-45929] = "fixed-version: only affects 6.16 onwards"
 
-# CVE-2026-45930 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-45930] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-45931] = "fixed-version: only affects 6.14 onwards"
 
@@ -23714,7 +23714,7 @@ CVE_STATUS[CVE-2026-46052] = "cpe-stable-backport: Backported in 6.6.140"
 
 CVE_STATUS[CVE-2026-46053] = "cpe-stable-backport: Backported in 6.6.140"
 
-# CVE-2026-46054 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46054] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-46055] = "fixed-version: only affects 7.0 onwards"
 
@@ -23790,7 +23790,7 @@ CVE_STATUS[CVE-2026-46089] = "cpe-stable-backport: Backported in 6.6.140"
 
 CVE_STATUS[CVE-2026-46091] = "cpe-stable-backport: Backported in 6.6.140"
 
-# CVE-2026-46092 needs backporting (fixed from 7.1)
+CVE_STATUS[CVE-2026-46092] = "cpe-stable-backport: Backported in 6.6.140"
 
 CVE_STATUS[CVE-2026-46093] = "fixed-version: only affects 6.9 onwards"
 
@@ -23876,7 +23876,7 @@ CVE_STATUS[CVE-2026-46133] = "cpe-stable-backport: Backported in 6.6.140"
 
 CVE_STATUS[CVE-2026-46134] = "fixed-version: only affects 6.14 onwards"
 
-# CVE-2026-46135 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46135] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-46136] = "cpe-stable-backport: Backported in 6.6.140"
 
@@ -23886,7 +23886,7 @@ CVE_STATUS[CVE-2026-46138] = "cpe-stable-backport: Backported in 6.6.140"
 
 CVE_STATUS[CVE-2026-46139] = "fixed-version: only affects 6.12.23 onwards"
 
-# CVE-2026-46140 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46140] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-46141] = "fixed-version: only affects 6.18 onwards"
 
@@ -24086,7 +24086,7 @@ CVE_STATUS[CVE-2026-46240] = "fixed-version: only affects 6.18.16 onwards"
 
 # CVE-2026-46241 needs backporting (fixed from 7.1)
 
-# CVE-2026-46242 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46242] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-46243] = "cpe-stable-backport: Backported in 6.6.142"
 
@@ -24106,7 +24106,7 @@ CVE_STATUS[CVE-2026-46250] = "cpe-stable-backport: Backported in 6.6.128"
 
 CVE_STATUS[CVE-2026-46251] = "cpe-stable-backport: Backported in 6.6.128"
 
-# CVE-2026-46252 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46252] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-46253] = "cpe-stable-backport: Backported in 6.6.128"
 
@@ -24242,11 +24242,11 @@ CVE_STATUS[CVE-2026-46318] = "fixed-version: only affects 6.19 onwards"
 
 CVE_STATUS[CVE-2026-46319] = "cpe-stable-backport: Backported in 6.6.141"
 
-# CVE-2026-46320 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-46320] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-46321 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-46321] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-46322 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-46322] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-46323] = "cpe-stable-backport: Backported in 6.6.142"
 
@@ -24264,7 +24264,7 @@ CVE_STATUS[CVE-2026-46329] = "fixed-version: only affects 6.12 onwards"
 
 # CVE-2026-46330 needs backporting (fixed from 7.0)
 
-# CVE-2026-46331 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46331] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-46332] = "fixed-version: only affects 6.12 onwards"
 
@@ -24278,17 +24278,17 @@ CVE_STATUS[CVE-2026-52906] = "fixed-version: only affects 6.19 onwards"
 
 CVE_STATUS[CVE-2026-52907] = "fixed-version: only affects 6.19 onwards"
 
-# CVE-2026-52908 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52908] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-52909 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-52909] = "cpe-stable-backport: Backported in 6.6.144"
 
-# CVE-2026-52910 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52910] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-52911] = "cpe-stable-backport: Backported in 6.6.141"
 
 CVE_STATUS[CVE-2026-52912] = "cpe-stable-backport: Backported in 6.6.142"
 
-# CVE-2026-52913 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52913] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-52914] = "cpe-stable-backport: Backported in 6.6.142"
 
@@ -24296,7 +24296,7 @@ CVE_STATUS[CVE-2026-52915] = "cpe-stable-backport: Backported in 6.6.142"
 
 CVE_STATUS[CVE-2026-52916] = "cpe-stable-backport: Backported in 6.6.142"
 
-# CVE-2026-52917 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52917] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-52918] = "cpe-stable-backport: Backported in 6.6.142"
 
@@ -24308,21 +24308,21 @@ CVE_STATUS[CVE-2026-52921] = "cpe-stable-backport: Backported in 6.6.142"
 
 CVE_STATUS[CVE-2026-52922] = "cpe-stable-backport: Backported in 6.6.142"
 
-# CVE-2026-52923 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52923] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-52924 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52924] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-52925] = "cpe-stable-backport: Backported in 6.6.141"
 
 CVE_STATUS[CVE-2026-52926] = "cpe-stable-backport: Backported in 6.6.142"
 
-# CVE-2026-52927 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52927] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-52928 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-52928] = "cpe-stable-backport: Backported in 6.6.144"
 
-# CVE-2026-52929 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52929] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-52930 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52930] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-52931] = "cpe-stable-backport: Backported in 6.6.142"
 
@@ -24330,9 +24330,9 @@ CVE_STATUS[CVE-2026-52932] = "fixed-version: only affects 6.15 onwards"
 
 CVE_STATUS[CVE-2026-52933] = "cpe-stable-backport: Backported in 6.6.140"
 
-# CVE-2026-52934 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52934] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-52935 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52935] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-52936] = "cpe-stable-backport: Backported in 6.6.141"
 
@@ -24340,25 +24340,25 @@ CVE_STATUS[CVE-2026-52936] = "cpe-stable-backport: Backported in 6.6.141"
 
 CVE_STATUS[CVE-2026-52938] = "fixed-version: only affects 7.0 onwards"
 
-# CVE-2026-52939 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52939] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-52940] = "fixed-version: only affects 6.17 onwards"
 
 CVE_STATUS[CVE-2026-52941] = "cpe-stable-backport: Backported in 6.6.142"
 
-# CVE-2026-52942 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52942] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-52943 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52943] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-52944 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52944] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-52945] = "fixed-version: only affects 6.15.3 onwards"
 
-# CVE-2026-52946 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52946] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-52947 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52947] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-52948 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52948] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-52949] = "fixed-version: only affects 6.15 onwards"
 
@@ -24622,7 +24622,7 @@ CVE_STATUS[CVE-2026-53077] = "cpe-stable-backport: Backported in 6.6.141"
 
 CVE_STATUS[CVE-2026-53079] = "fixed-version: only affects 6.19 onwards"
 
-# CVE-2026-53080 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53080] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53081] = "fixed-version: only affects 6.11 onwards"
 
@@ -24724,23 +24724,23 @@ CVE_STATUS[CVE-2026-53128] = "cpe-stable-backport: Backported in 6.6.141"
 
 CVE_STATUS[CVE-2026-53130] = "cpe-stable-backport: Backported in 6.6.141"
 
-# CVE-2026-53131 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53131] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-53132 needs backporting (fixed from 7.1)
 
-# CVE-2026-53133 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53133] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53134 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53134] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53135 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53135] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53136 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53136] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53137 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53137] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53138 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53138] = "cpe-stable-backport: Backported in 6.6.144"
 
-# CVE-2026-53139 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53139] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-53140] = "fixed-version: only affects 6.8 onwards"
 
@@ -24748,57 +24748,55 @@ CVE_STATUS[CVE-2026-53141] = "fixed-version: only affects 6.14 onwards"
 
 CVE_STATUS[CVE-2026-53142] = "fixed-version: only affects 6.8 onwards"
 
-# CVE-2026-53143 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53143] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53144 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53144] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53145] = "fixed-version: only affects 6.18.32 onwards"
 
-# CVE-2026-53146 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53146] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53147 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53147] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53148 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53148] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53149 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53149] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53150 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53150] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53151 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53151] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-53152] = "fixed-version: only affects 6.12.78 onwards"
 
 CVE_STATUS[CVE-2026-53153] = "fixed-version: only affects 6.13 onwards"
 
-# CVE-2026-53154 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53154] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53155] = "fixed-version: only affects 6.19 onwards"
 
 # CVE-2026-53156 needs backporting (fixed from 7.1)
 
-# CVE-2026-53157 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53157] = "cpe-stable-backport: Backported in 6.6.144"
 
-# CVE-2026-53158 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53158] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53159 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53159] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53160 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53160] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53161 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53161] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53162] = "fixed-version: only affects 6.16 onwards"
 
-# CVE-2026-53163 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53163] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-53164] = "fixed-version: only affects 6.16 onwards"
 
 CVE_STATUS[CVE-2026-53165] = "fixed-version: only affects 7.0 onwards"
 
-# CVE-2026-53166 may need backporting (fixed from 6.7)
+CVE_STATUS[CVE-2026-53167] = "cpe-stable-backport: Backported in 6.6.144"
 
-# CVE-2026-53167 may need backporting (fixed from 6.6.144)
-
-# CVE-2026-53168 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53168] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53169] = "fixed-version: only affects 6.19 onwards"
 
@@ -24814,9 +24812,9 @@ CVE_STATUS[CVE-2026-53174] = "fixed-version: only affects 6.19 onwards"
 
 CVE_STATUS[CVE-2026-53175] = "fixed-version: only affects 6.12.93 onwards"
 
-# CVE-2026-53176 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53176] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53177 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53177] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-53178 needs backporting (fixed from 7.1)
 
@@ -24824,25 +24822,25 @@ CVE_STATUS[CVE-2026-53175] = "fixed-version: only affects 6.12.93 onwards"
 
 CVE_STATUS[CVE-2026-53180] = "fixed-version: only affects 6.9 onwards"
 
-# CVE-2026-53181 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53181] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53182 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53182] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53183 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53183] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53184 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53184] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53185 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53185] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53186 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53186] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53187] = "fixed-version: only affects 6.17 onwards"
 
 CVE_STATUS[CVE-2026-53188] = "fixed-version: only affects 6.15 onwards"
 
-# CVE-2026-53189 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53189] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53190 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53190] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53191] = "fixed-version: only affects 6.12 onwards"
 
@@ -24850,17 +24848,17 @@ CVE_STATUS[CVE-2026-53192] = "fixed-version: only affects 6.12 onwards"
 
 CVE_STATUS[CVE-2026-53193] = "fixed-version: only affects 6.12 onwards"
 
-# CVE-2026-53194 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53194] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53195 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53195] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53196 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53196] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53197] = "fixed-version: only affects 6.14 onwards"
 
-# CVE-2026-53198 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53198] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53199 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53199] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53200] = "fixed-version: only affects 6.19 onwards"
 
@@ -24876,57 +24874,57 @@ CVE_STATUS[CVE-2026-53205] = "fixed-version: only affects 6.12.30 onwards"
 
 CVE_STATUS[CVE-2026-53206] = "fixed-version: only affects 6.19 onwards"
 
-# CVE-2026-53207 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53207] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53208 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53208] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53209 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53209] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53210] = "fixed-version: only affects 6.8 onwards"
 
 CVE_STATUS[CVE-2026-53211] = "fixed-version: only affects 6.18 onwards"
 
-# CVE-2026-53212 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53212] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53213 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53213] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53214 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53214] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53215 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53215] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53216 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53216] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53217 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53217] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53218 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53218] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53219 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53219] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-53220 needs backporting (fixed from 7.1)
 
-# CVE-2026-53221 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53221] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53222] = "fixed-version: only affects 6.18 onwards"
 
-# CVE-2026-53223 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53223] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-53224 needs backporting (fixed from 7.1)
 
-# CVE-2026-53225 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53225] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-53226 needs backporting (fixed from 7.1)
 
-# CVE-2026-53227 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53227] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53228 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53228] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-53229 needs backporting (fixed from 7.1)
 
-# CVE-2026-53230 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53230] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53231] = "fixed-version: only affects 7.0 onwards"
 
-# CVE-2026-53232 needs backporting (fixed from 7.1)
+CVE_STATUS[CVE-2026-53232] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53233] = "fixed-version: only affects 6.12 onwards"
 
@@ -24934,47 +24932,47 @@ CVE_STATUS[CVE-2026-53234] = "fixed-version: only affects 6.12 onwards"
 
 CVE_STATUS[CVE-2026-53235] = "fixed-version: only affects 6.10 onwards"
 
-# CVE-2026-53236 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53236] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53237 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53237] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53238 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53238] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53239 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53239] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53240] = "fixed-version: only affects 6.14 onwards"
 
 CVE_STATUS[CVE-2026-53241] = "fixed-version: only affects 6.10 onwards"
 
-# CVE-2026-53242 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53242] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53243] = "fixed-version: only affects 7.0.10 onwards"
 
 CVE_STATUS[CVE-2026-53244] = "fixed-version: only affects 7.0 onwards"
 
-# CVE-2026-53245 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53245] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-53246 needs backporting (fixed from 7.1)
 
-# CVE-2026-53247 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53247] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53248] = "fixed-version: only affects 6.15 onwards"
 
-# CVE-2026-53249 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53249] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53250] = "fixed-version: only affects 6.8 onwards"
 
 CVE_STATUS[CVE-2026-53251] = "fixed-version: only affects 6.12.2 onwards"
 
-# CVE-2026-53252 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53252] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53253 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53253] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53254 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53254] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53255 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53255] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53256 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53256] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53257] = "fixed-version: only affects 6.16 onwards"
 
@@ -24988,31 +24986,31 @@ CVE_STATUS[CVE-2026-53261] = "fixed-version: only affects 6.7 onwards"
 
 # CVE-2026-53262 needs backporting (fixed from 7.1)
 
-# CVE-2026-53263 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53263] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53264 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53264] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53265 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53265] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53266 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53266] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53267 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53267] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53268 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53268] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53269 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53269] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53270 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53270] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53271 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53271] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-53272 needs backporting (fixed from 7.1)
 
-# CVE-2026-53273 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53273] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53274 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53274] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53275 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53275] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53276] = "fixed-version: only affects 6.19 onwards"
 
@@ -25112,19 +25110,19 @@ CVE_STATUS[CVE-2026-53323] = "fixed-version: only affects 6.15 onwards"
 
 CVE_STATUS[CVE-2026-53324] = "fixed-version: only affects 6.13 onwards"
 
-# CVE-2026-53325 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53325] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-53326] = "fixed-version: only affects 6.19 onwards"
 
-# CVE-2026-53327 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53327] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-53328] = "fixed-version: only affects 6.12 onwards"
 
-# CVE-2026-53329 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53329] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-53330 needs backporting (fixed from 7.1)
 
-# CVE-2026-53331 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53331] = "cpe-stable-backport: Backported in 6.6.143"
 
 # CVE-2026-53332 needs backporting (fixed from 7.1)
 
@@ -25134,13 +25132,13 @@ CVE_STATUS[CVE-2026-53334] = "fixed-version: only affects 6.18 onwards"
 
 CVE_STATUS[CVE-2026-53335] = "fixed-version: only affects 6.18 onwards"
 
-# CVE-2026-53336 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53336] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53337 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53337] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53338] = "fixed-version: only affects 6.16 onwards"
 
-# CVE-2026-53339 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53339] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53340] = "fixed-version: only affects 6.14 onwards"
 
@@ -25148,43 +25146,933 @@ CVE_STATUS[CVE-2026-53341] = "fixed-version: only affects 6.11 onwards"
 
 CVE_STATUS[CVE-2026-53342] = "fixed-version: only affects 6.16 onwards"
 
-# CVE-2026-53343 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53343] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53344] = "fixed-version: only affects 6.19 onwards"
 
-# CVE-2026-53345 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53345] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53346] = "fixed-version: only affects 6.12 onwards"
 
-# CVE-2026-53347 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53347] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53348] = "fixed-version: only affects 6.19 onwards"
 
-# CVE-2026-53349 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53349] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53350 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53350] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53351] = "fixed-version: only affects 7.0 onwards"
 
-# CVE-2026-53352 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53352] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53353 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53353] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53354 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53354] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53355 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53355] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53356 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53356] = "cpe-stable-backport: Backported in 6.6.143"
 
 CVE_STATUS[CVE-2026-53357] = "cpe-stable-backport: Backported in 6.6.142"
 
-# CVE-2026-53358 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53358] = "cpe-stable-backport: Backported in 6.6.143"
 
-# CVE-2026-53359 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53359] = "cpe-stable-backport: Backported in 6.6.144"
 
 CVE_STATUS[CVE-2026-53360] = "fixed-version: only affects 6.10 onwards"
 
-# CVE-2026-53361 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53361] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53362] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53363] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-53364] = "fixed-version: only affects 6.16.4 onwards"
+
+CVE_STATUS[CVE-2026-53365] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-53366] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53367] = "fixed-version: only affects 6.17.10 onwards"
+
+# CVE-2026-53368 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-53369] = "cpe-stable-backport: Backported in 6.6.140"
+
+CVE_STATUS[CVE-2026-53370] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-53371] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-53372] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-53373] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-53374] = "cpe-stable-backport: Backported in 6.6.140"
+
+CVE_STATUS[CVE-2026-53375] = "cpe-stable-backport: Backported in 6.6.140"
+
+CVE_STATUS[CVE-2026-53376] = "cpe-stable-backport: Backported in 6.6.140"
+
+# CVE-2026-53377 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-53378] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-53379] = "cpe-stable-backport: Backported in 6.6.140"
+
+CVE_STATUS[CVE-2026-53380] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-53381] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53382] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53383] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53384] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53385] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53386] = "fixed-version: only affects 6.9 onwards"
+
+CVE_STATUS[CVE-2026-53387] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-53388] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53389] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-53390] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53391] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-53392 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-53393 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-53394] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-53395] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-53396] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-53397] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53398] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-53399 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-53400 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-53401 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-53402 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-53403] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63793] = "fixed-version: only affects 7.1 onwards"
+
+CVE_STATUS[CVE-2026-63794] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63795] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63796] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63797] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63798] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63799] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63800] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63801] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63802] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63803] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63804] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63805 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-63806 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63807] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63808] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63809] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63810 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-63811 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63812] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63813] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63814] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63815 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-63816 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63817] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63818 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-63819 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63820] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63821] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63822] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63823] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63824] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63825 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63826] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63827] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63828] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63829 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63830] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63831] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63832] = "fixed-version: only affects 6.12.13 onwards"
+
+CVE_STATUS[CVE-2026-63833] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63834] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63835] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63836] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63837] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-63838] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63839] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-63840] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63841] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-63842] = "fixed-version: only affects 6.9 onwards"
+
+CVE_STATUS[CVE-2026-63843] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-63844] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63845] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63846] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63847] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63848] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63849] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-63850] = "fixed-version: only affects 6.9 onwards"
+
+CVE_STATUS[CVE-2026-63851] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-63852] = "cpe-stable-backport: Backported in 6.6.141"
+
+# CVE-2026-63853 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63854] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63855] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63856] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63857] = "fixed-version: only affects 6.11 onwards"
+
+# CVE-2026-63858 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63859] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63860] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63861] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63862] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63863] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63864] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63865] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63866] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63867] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63868] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63869] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-63870] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-63871 needs backporting (fixed from 7.1)
+
+# CVE-2026-63872 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63873] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-63874] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63875] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63876] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63877] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63878] = "fixed-version: only affects 6.18 onwards"
+
+# CVE-2026-63879 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63880] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-63881] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63882] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63883] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63884] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63885] = "fixed-version: only affects 6.18.32 onwards"
+
+CVE_STATUS[CVE-2026-63886] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63887] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63888] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63889] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63890] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63891] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63892] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63893] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63894] = "fixed-version: only affects 6.9 onwards"
+
+CVE_STATUS[CVE-2026-63895] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63896] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63897] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63898] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63899] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63900] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63901] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63902] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63903] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63904] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63905] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63906] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63907] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63908] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63909] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63910] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63911] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-63912] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63913] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63914] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63915] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63916] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63917] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63918] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-63919] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63920] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63921] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63922] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63923] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-63924] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63925] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63926] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63927] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63928] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63929] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63930] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63931] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63932] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-63933] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63934] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63935] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63936] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63937] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63938] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63939] = "fixed-version: only affects 6.11 onwards"
+
+# CVE-2026-63940 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63941] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63942] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63943] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63944] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63945] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63946] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63947] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63948] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63949] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63950] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63951] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63952] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63953] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63954] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63955] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63956] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63957] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63958] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63959] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63960] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63961] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-63962 needs backporting (fixed from 7.1)
+
+# CVE-2026-63963 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63964] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63965] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-63966] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63967] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63968] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63969] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63970] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-63971] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63972] = "fixed-version: only affects 6.18.33 onwards"
+
+CVE_STATUS[CVE-2026-63973] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-63974 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63975] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63976] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63977] = "fixed-version: only affects 6.18 onwards"
+
+# CVE-2026-63978 needs backporting (fixed from 7.1)
+
+# CVE-2026-63979 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63980] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-63981] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63982] = "fixed-version: only affects 6.19 onwards"
+
+# CVE-2026-63983 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63984] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63985] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63986] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-63987] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63988] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63989] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63990] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63991] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63992] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63993] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63994] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63995] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63996] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63997] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63998] = "fixed-version: only affects 6.11 onwards"
+
+# CVE-2026-63999 may need backporting (fixed from 6.7)
+
+CVE_STATUS[CVE-2026-64000] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-64001 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64002] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64003] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64004] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64005] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64006] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64007] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64008] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64009] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64010] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64011] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64012] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64013] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64014] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64015] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64016] = "fixed-version: only affects 6.18.33 onwards"
+
+# CVE-2026-64017 may need backporting (fixed from 6.7)
+
+CVE_STATUS[CVE-2026-64018] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64019] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-64020] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-64021] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-64022] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64023] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64024] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64025] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64026] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64027] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-64028] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64029] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64030] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64031] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64032] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64033] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64034] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64035] = "fixed-version: only affects 6.16 onwards"
+
+# CVE-2026-64036 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64037] = "fixed-version: only affects 6.15 onwards"
+
+# CVE-2026-64038 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64039] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64040] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64041] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64042] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64043] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64044] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64045] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64046] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64047] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64048] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64049] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-64050] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64051] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64052] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-64053] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-64054] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-64055] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64056] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64057] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-64058] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64059] = "fixed-version: only affects 6.12 onwards"
+
+# CVE-2026-64060 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64061] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64062] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64063] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64064] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-64065] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64066] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64067] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64068] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64069] = "fixed-version: only affects 6.14 onwards"
+
+# CVE-2026-64070 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64071] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-64072] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64073] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64074] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64075] = "fixed-version: only affects 6.14 onwards"
+
+# CVE-2026-64076 needs backporting (fixed from 7.1)
+
+# CVE-2026-64077 needs backporting (fixed from 7.1)
+
+# CVE-2026-64078 needs backporting (fixed from 7.1)
+
+# CVE-2026-64079 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64080] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64081] = "fixed-version: only affects 6.15 onwards"
+
+# CVE-2026-64082 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64083] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64084] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64085] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64086] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64087] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64088] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64089] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64090] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64091] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64092] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64093] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64094] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64095] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64096] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64097] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64098] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64099] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-64100] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-64101] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64102] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64103] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64104] = "fixed-version: only affects 6.13.8 onwards"
+
+CVE_STATUS[CVE-2026-64105] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64106] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64107] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64108] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64109] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64110] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64111] = "fixed-version: only affects 6.8 onwards"
+
+# CVE-2026-64112 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64113] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64114] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64115] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64116] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-64117 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64118] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64119] = "fixed-version: only affects 6.11.3 onwards"
+
+CVE_STATUS[CVE-2026-64120] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64121] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64122] = "fixed-version: only affects 6.18.14 onwards"
+
+CVE_STATUS[CVE-2026-64123] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64124] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64125] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64126] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64127] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64128] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64129] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64130] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64131] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64132] = "fixed-version: only affects 6.9 onwards"
+
+CVE_STATUS[CVE-2026-64133] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64134] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64135] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64136] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64137] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-64138 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64139] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64140] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-64141] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64142] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-64143] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64144] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64145] = "fixed-version: only affects 6.13 onwards"
+
+# CVE-2026-64146 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64147] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64148] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64149] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64150] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64151] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64152] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-64153] = "cpe-stable-backport: Backported in 6.6.142"
+
+# CVE-2026-64154 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64155] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64156] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-64157] = "fixed-version: only affects 6.10.8 onwards"
+
+CVE_STATUS[CVE-2026-64158] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-64159] = "fixed-version: only affects 6.10.8 onwards"
+
+# CVE-2026-64160 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64161] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64162] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64163] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64164] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64165] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64166] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64167] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64168] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64169] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64170] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64171] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-64172] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-64173] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64174] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64175] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64176] = "fixed-version: only affects 6.17.9 onwards"
+
+CVE_STATUS[CVE-2026-64177] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64178] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64179] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64180] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-64181] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64182] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64183] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64184] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64185] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64186] = "fixed-version: only affects 6.17 onwards"
+
+# CVE-2026-64187 needs backporting (fixed from 7.2rc4)
+
+CVE_STATUS[CVE-2026-64188] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-64189 needs backporting (fixed from 7.2rc2)
+
+# CVE-2026-64190 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64191] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-64192 needs backporting (fixed from 7.2rc2)
+
+# CVE-2026-64205 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-64206 needs backporting (fixed from 7.2rc3)
+
+CVE_STATUS[CVE-2026-64207] = "fixed-version: only affects 6.17 onwards"
 
-# CVE-2026-53362 may need backporting (fixed from 6.6.144)
+# CVE-2026-64600 needs backporting (fixed from 7.2rc4)
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 05/31] libxml2: Fix CVE-2026-11979
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (3 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 04/31] linux-yocto/6.6: update CVE exclusions (6.6.144) Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 06/31] openssh: Fix CVE-2026-59999 Yoann Congal
                   ` (25 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Devansh Patel <devanshp@cisco.com>

This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].

[1] https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-11979

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../libxml/libxml2/CVE-2026-11979.patch       | 70 +++++++++++++++++++
 meta/recipes-core/libxml/libxml2_2.12.10.bb   |  1 +
 2 files changed, 71 insertions(+)
 create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch

diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
new file mode 100644
index 00000000000..427026b345f
--- /dev/null
+++ b/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
@@ -0,0 +1,70 @@
+From d8566dd918c612078dfb3ee1a95d7bb6f0656bfe Mon Sep 17 00:00:00 2001
+From: Daniel Garcia Moreno <daniel.garcia@suse.com>
+Date: Fri, 22 May 2026 12:21:20 +0200
+Subject: [PATCH] xmlcatalog: overflow check for large --shell commands
+
+Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124
+
+CVE: CVE-2026-11979
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e]
+
+Backport Changes:
+- The commit modifies test/catalogs/test.sh.
+- test/catalogs/test.sh does not exist in the libxml2 v2.12.10
+  source used in Scarthgap and was introduced later version
+  libxml2 v2.14.0 [1].
+- The test changes were omitted; only the required fix in
+  xmlcatalog.c was backported.
+
+[1] https://gitlab.gnome.org/GNOME/libxml2/-/commit/f06fc933cdaea2ce8e9cea275fdbf4edb85f9837
+
+(cherry picked from commit c2e233fc1b341685fc99621b2768b503f777a72e)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ xmlcatalog.c | 16 ++++++++++++++++
+ 1 file changed, 16 insertions(+)
+
+diff --git a/xmlcatalog.c b/xmlcatalog.c
+index 588802b41..51569b879 100644
+--- a/xmlcatalog.c
++++ b/xmlcatalog.c
+@@ -114,6 +114,12 @@ static void usershell(void) {
+ 	       (*cur != '\n') && (*cur != '\r')) {
+ 	    if (*cur == 0)
+ 		break;
++            /* Do not read beyond the command array capacity */
++            if (i >= (int)sizeof(command) - 2) {
++                printf("Invalid command %s\n", cur);
++                i = 0;
++                break;
++            }
+ 	    command[i++] = *cur++;
+ 	}
+ 	command[i] = 0;
+@@ -131,6 +137,11 @@ static void usershell(void) {
+ 	while ((*cur != '\n') && (*cur != '\r') && (*cur != 0)) {
+ 	    if (*cur == 0)
+ 		break;
++            if (i >= (int)sizeof(arg) - 2) {
++                printf("Invalid arg %s\n", arg);
++                i = 0;
++                break;
++            }
+ 	    arg[i++] = *cur++;
+ 	}
+ 	arg[i] = 0;
+@@ -143,6 +154,11 @@ static void usershell(void) {
+ 	cur = arg;
+ 	memset(argv, 0, sizeof(argv));
+ 	while (*cur != 0) {
++            if (i >= (int)sizeof(argv) / (int)sizeof(char*)) {
++                printf("Too much arguments\n");
++                break;
++            }
++
+ 	    while ((*cur == ' ') || (*cur == '\t')) cur++;
+ 	    if (*cur == '\'') {
+ 		cur++;
+-- 
+2.35.6
+
diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb
index 2bfa78324f6..d476ba14b6e 100644
--- a/meta/recipes-core/libxml/libxml2_2.12.10.bb
+++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb
@@ -31,6 +31,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt
            file://CVE-2026-0992-02.patch \
            file://CVE-2026-0992-03.patch \
            file://CVE-2026-1757.patch \
+           file://CVE-2026-11979.patch \
            "
 
 SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995"


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 06/31] openssh: Fix CVE-2026-59999
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (4 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 05/31] libxml2: Fix CVE-2026-11979 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 07/31] openssh: Fix CVE-2026-59997 Yoann Congal
                   ` (24 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Devansh Patel <devanshp@cisco.com>

This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-59999. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59999

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../openssh/openssh/CVE-2026-59999.patch      | 36 +++++++++++++++++++
 .../openssh/openssh_9.6p1.bb                  |  1 +
 2 files changed, 37 insertions(+)
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch
new file mode 100644
index 00000000000..89b7aa9c7f4
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch
@@ -0,0 +1,36 @@
+From 1c719fa7d0fb0aa335f0e8d5db5d5e5d01c894e5 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Sun, 31 May 2026 04:47:29 +0000
+Subject: [PATCH] upstream: DisableForwarding=yes didn't override
+ PermitTunnel=yes
+
+Reported independently by Huzaifa Sidhpurwala of Redhat and Marko
+Jevtic; ok markus@
+
+CVE: CVE-2026-59999
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753]
+
+Backport Changes:
+- Retained the Scarthgap serverloop.c OpenBSD revision identifier because
+  the 10.4 identifier does not describe the older source baseline.
+
+OpenBSD-Commit-ID: b5c13f0746cf079b21f8deba47407fad49ccbf4c
+(cherry picked from commit 8dfe7ed6e2fd988de08df508355a196b956b2753)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ serverloop.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/serverloop.c b/serverloop.c
+index f3683c2e4..c1fe99d12 100644
+--- a/serverloop.c
++++ b/serverloop.c
+@@ -531,7 +531,7 @@ server_request_tun(struct ssh *ssh)
+ 		ssh_packet_send_debug(ssh, "Unsupported tunnel device mode.");
+ 		return NULL;
+ 	}
+-	if ((options.permit_tun & mode) == 0) {
++	if ((options.permit_tun & mode) == 0 || options.disable_forwarding) {
+ 		ssh_packet_send_debug(ssh, "Server has rejected tunnel device "
+ 		    "forwarding");
+ 		return NULL;
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 4ab3174924c..b6eda3607a9 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -37,6 +37,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
            file://CVE-2026-35385.patch \
            file://CVE-2026-35414-CVE-2026-35387.patch \
            file://CVE-2026-35388.patch \
+           file://CVE-2026-59999.patch \
            "
 SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 07/31] openssh: Fix CVE-2026-59997
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (5 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 06/31] openssh: Fix CVE-2026-59999 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 08/31] openssh: Fix CVE-2026-59996 Yoann Congal
                   ` (23 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Devansh Patel <devanshp@cisco.com>

This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-59997. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/openssh/openssh-portable/commit/e9916c44c1324ab9ab022719e4df08a390a83014
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59997

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../openssh/openssh/CVE-2026-59997.patch      | 58 +++++++++++++++++++
 .../openssh/openssh_9.6p1.bb                  |  1 +
 2 files changed, 59 insertions(+)
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch
new file mode 100644
index 00000000000..aa171def018
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch
@@ -0,0 +1,58 @@
+From 3011cbb6bb73f3f3dc90fa1d48736803fa407509 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Fri, 5 Jun 2026 08:53:07 +0000
+Subject: [PATCH] upstream: pass >9 commandline arguments to the internal-sftp
+ server,
+
+previously they were silently dropped; reported by Steve Caffrey ok deraadt@
+
+CVE: CVE-2026-59997
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/e9916c44c1324ab9ab022719e4df08a390a83014]
+
+Backport Changes:
+- Retained the Scarthgap session.c OpenBSD revision identifier because the
+  10.4 identifier does not describe the older source baseline.
+
+OpenBSD-Commit-ID: ee6cd5430a3ca027c3223af54b58ad3cc7ccd624
+(cherry picked from commit e9916c44c1324ab9ab022719e4df08a390a83014)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ session.c | 19 ++++++++++---------
+ 1 file changed, 10 insertions(+), 9 deletions(-)
+
+diff --git a/session.c b/session.c
+index eb932b8bf..1a01ecf74 100644
+--- a/session.c
++++ b/session.c
+@@ -1650,21 +1650,22 @@ do_child(struct ssh *ssh, Session *s, const char *command)
+ 		exit(1);
+ 	} else if (s->is_subsystem == SUBSYSTEM_INT_SFTP) {
+ 		extern int optind, optreset;
+-		int i;
+-		char *p, *args;
++		int sftp_argc;
++		char **sftp_argv;
+ 
+ 		setproctitle("%s@%s", s->pw->pw_name, INTERNAL_SFTP_NAME);
+-		args = xstrdup(command ? command : "sftp-server");
+-		for (i = 0, (p = strtok(args, " ")); p; (p = strtok(NULL, " ")))
+-			if (i < ARGV_MAX - 1)
+-				argv[i++] = p;
+-		argv[i] = NULL;
++		if (argv_split(command == NULL ? "sftp-server" : command,
++		    &sftp_argc, &sftp_argv, 1) != 0) {
++			error("internal error: can't split internal-sftp "
++			    "arguments");
++			exit(1);
++		}
+ 		optind = optreset = 1;
+-		__progname = argv[0];
++		__progname = sftp_argv[0];
+ #ifdef WITH_SELINUX
+ 		ssh_selinux_change_context("sftpd_t");
+ #endif
+-		exit(sftp_server_main(i, argv, s->pw));
++		exit(sftp_server_main(sftp_argc, sftp_argv, s->pw));
+ 	}
+ 
+ 	fflush(NULL);
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index b6eda3607a9..4c8604f4b74 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -38,6 +38,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
            file://CVE-2026-35414-CVE-2026-35387.patch \
            file://CVE-2026-35388.patch \
            file://CVE-2026-59999.patch \
+           file://CVE-2026-59997.patch \
            "
 SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 08/31] openssh: Fix CVE-2026-59996
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (6 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 07/31] openssh: Fix CVE-2026-59997 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 09/31] openssh: Fix CVE-2026-59995 Yoann Congal
                   ` (22 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Devansh Patel <devanshp@cisco.com>

This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-59996. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/openssh/openssh-portable/commit/36480181fa22f98e180b4f9e10203480c0346c78
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59996

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../openssh/openssh/CVE-2026-59996.patch      | 37 +++++++++++++++++++
 .../openssh/openssh_9.6p1.bb                  |  1 +
 2 files changed, 38 insertions(+)
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch
new file mode 100644
index 00000000000..b13390b25b7
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch
@@ -0,0 +1,37 @@
+From 762b3d438547893d62ce3e147dce6cef14697b09 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Sun, 28 Jun 2026 23:47:16 +0000
+Subject: [PATCH] upstream: resist that return ".." via remote glob during
+
+remote/remote copies, similar to fixes for bz3871 for remote/local copies.
+From Swival scanner
+
+CVE: CVE-2026-59996
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/36480181fa22f98e180b4f9e10203480c0346c78]
+
+Backport Changes:
+- Retained the Scarthgap scp.c OpenBSD revision identifier because the
+  10.4 identifier does not describe the older source baseline.
+
+OpenBSD-Commit-ID: c0c20a1b746db55c08e53658bf21ea9405b300a5
+(cherry picked from commit 36480181fa22f98e180b4f9e10203480c0346c78)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ scp.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/scp.c b/scp.c
+index 2c21fa19a..00d87517d 100644
+--- a/scp.c
++++ b/scp.c
+@@ -2043,6 +2043,10 @@ throughlocal_sftp(struct sftp_conn *from, struct sftp_conn *to,
+ 			goto out;
+ 		}
+ 
++		/* Special handling for source of '..' */
++		if (strcmp(filename, "..") == 0)
++			filename = "."; /* Download to dest, not dest/.. */
++
+ 		if (targetisdir)
+ 			abs_dst = sftp_path_append(target, filename);
+ 		else
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 4c8604f4b74..8f44d4b9878 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -39,6 +39,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
            file://CVE-2026-35388.patch \
            file://CVE-2026-59999.patch \
            file://CVE-2026-59997.patch \
+           file://CVE-2026-59996.patch \
            "
 SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 09/31] openssh: Fix CVE-2026-59995
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (7 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 08/31] openssh: Fix CVE-2026-59996 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 10/31] openssh: Fix CVE-2026-60001 Yoann Congal
                   ` (21 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Devansh Patel <devanshp@cisco.com>

This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-59995. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59995

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../openssh/openssh/CVE-2026-59995.patch      | 42 +++++++++++++++++++
 .../openssh/openssh_9.6p1.bb                  |  1 +
 2 files changed, 43 insertions(+)
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch
new file mode 100644
index 00000000000..9b6fee198ff
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch
@@ -0,0 +1,42 @@
+From b340eaa274a7e7dffea03bcb62169249bbddab37 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Mon, 29 Jun 2026 01:47:21 +0000
+Subject: [PATCH] upstream: avoid download to server-controlled path when
+ performing
+
+download on the commandline. From Swival scanner
+
+CVE: CVE-2026-59995
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b]
+
+Backport Changes:
+- Retained the Scarthgap sftp.c OpenBSD revision identifier because the
+  10.4 identifier does not describe the older source baseline.
+
+OpenBSD-Commit-ID: d1b2c44305fdfe6d51eed9ecc727e59478bf311f
+(cherry picked from commit 1b39f39657d2e58f8ec57341581a39bbf0be645b)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ sftp.c | 9 ++-------
+ 1 file changed, 2 insertions(+), 7 deletions(-)
+
+diff --git a/sftp.c b/sftp.c
+index c609b4153..487e53976 100644
+--- a/sftp.c
++++ b/sftp.c
+@@ -2268,13 +2268,8 @@ interactive_loop(struct sftp_conn *conn, char *file1, char *file2)
+ 				return (-1);
+ 			}
+ 		} else {
+-			/* XXX this is wrong wrt quoting */
+-			snprintf(cmd, sizeof cmd, "get%s %s%s%s",
+-			    global_aflag ? " -a" : "", dir,
+-			    file2 == NULL ? "" : " ",
+-			    file2 == NULL ? "" : file2);
+-			err = parse_dispatch_command(conn, cmd,
+-			    &remote_path, startdir, 1, 0);
++			err = process_get(conn, dir, file2, remote_path, 0, 0,
++			    global_aflag, 0);
+ 			free(dir);
+ 			free(startdir);
+ 			free(remote_path);
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 8f44d4b9878..37f4dc20dd9 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -40,6 +40,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
            file://CVE-2026-59999.patch \
            file://CVE-2026-59997.patch \
            file://CVE-2026-59996.patch \
+           file://CVE-2026-59995.patch \
            "
 SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 10/31] openssh: Fix CVE-2026-60001
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (8 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 09/31] openssh: Fix CVE-2026-59995 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 11/31] openssh: Fix CVE-2026-60002 Yoann Congal
                   ` (20 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Devansh Patel <devanshp@cisco.com>

This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-60001. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/openssh/openssh-portable/commit/d43ba60c91cb323ca921049b7d43b1908c318454
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-60001

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../openssh/openssh/CVE-2026-60001.patch      | 130 ++++++++++++++++++
 .../openssh/openssh_9.6p1.bb                  |   1 +
 2 files changed, 131 insertions(+)
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch
new file mode 100644
index 00000000000..ff1d14c7c9b
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch
@@ -0,0 +1,130 @@
+From ef41798b35a53757f8aa08ad14ee1463b0fe9b15 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Mon, 6 Jul 2026 07:44:48 +0000
+Subject: [PATCH] upstream: Fix cases in GSSAPI and keyboard-interactive
+
+authentication where the minimum per-attempt delay was not being enforced.
+
+Reported by Orange Cyberdefense Vulnerability Team
+
+CVE: CVE-2026-60001
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/d43ba60c91cb323ca921049b7d43b1908c318454]
+
+Backport Changes:
+- Kept Scarthgap's PRIVSEP(ssh_gssapi_userok()) interface and GSSAPI
+  display-name recording while adding the upstream failure-delay calls;
+  mm_ssh_gssapi_userok() belongs to the later split-sshd architecture.
+- Retained the Scarthgap OpenBSD revision identifiers in auth.h,
+  auth2-chall.c, auth2-gss.c, and auth2.c.
+
+OpenBSD-Commit-ID: c40bd35cc2428fcaccad7a141703c28baa6da01e
+(cherry picked from commit d43ba60c91cb323ca921049b7d43b1908c318454)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ auth.h        |  1 +
+ auth2-chall.c |  4 ++++
+ auth2-gss.c   |  7 +++++++
+ auth2.c       | 10 ++++++++--
+ 4 files changed, 20 insertions(+), 2 deletions(-)
+
+diff --git a/auth.h b/auth.h
+index 6d2d39762..9ad4898c5 100644
+--- a/auth.h
++++ b/auth.h
+@@ -173,6 +173,7 @@ void	auth_log(struct ssh *, int, int, const char *, const char *);
+ void	auth_maxtries_exceeded(struct ssh *) __attribute__((noreturn));
+ void	userauth_finish(struct ssh *, int, const char *, const char *);
+ int	auth_root_allowed(struct ssh *, const char *);
++void	auth_failure_delay(Authctxt *, double);
+ 
+ char	*auth2_read_banner(void);
+ int	 auth2_methods_valid(const char *, int);
+diff --git a/auth2-chall.c b/auth2-chall.c
+index 021df8291..20e70d222 100644
+--- a/auth2-chall.c
++++ b/auth2-chall.c
+@@ -296,6 +296,7 @@ input_userauth_info_response(int type, u_int32_t seq, struct ssh *ssh)
+ 	u_int i, nresp;
+ 	const char *devicename = NULL;
+ 	char **response = NULL;
++	double tstart = monotime_double();
+ 
+ 	if (authctxt == NULL)
+ 		fatal_f("no authctxt");
+@@ -354,6 +355,9 @@ input_userauth_info_response(int type, u_int32_t seq, struct ssh *ssh)
+ 			auth2_challenge_start(ssh);
+ 		}
+ 	}
++
++	if (!authenticated)
++		auth_failure_delay(authctxt, tstart);
+ 	userauth_finish(ssh, authenticated, "keyboard-interactive",
+ 	    devicename);
+ 	return 0;
+diff --git a/auth2-gss.c b/auth2-gss.c
+index f72a38998..195578bcf 100644
+--- a/auth2-gss.c
++++ b/auth2-gss.c
+@@ -255,6 +255,7 @@ input_gssapi_exchange_complete(int type, u_int32_t plen, struct ssh *ssh)
+ 	Authctxt *authctxt = ssh->authctxt;
+ 	int r, authenticated;
+ 	const char *displayname;
++	double tstart = monotime_double();
+ 
+ 	if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep))
+ 		fatal("No authentication or GSSAPI context");
+@@ -268,6 +269,8 @@ input_gssapi_exchange_complete(int type, u_int32_t plen, struct ssh *ssh)
+ 		fatal_fr(r, "parse packet");
+ 
+ 	authenticated = PRIVSEP(ssh_gssapi_userok(authctxt->user));
++	if (!authenticated)
++		auth_failure_delay(authctxt, tstart);
+ 
+ 	if ((!use_privsep || mm_is_monitor()) &&
+ 	    (displayname = ssh_gssapi_displayname()) != NULL)
+@@ -293,6 +296,7 @@ input_gssapi_mic(int type, u_int32_t plen, struct ssh *ssh)
+ 	const char *displayname;
+ 	u_char *p;
+ 	size_t len;
++	double tstart = monotime_double();
+ 
+ 	if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep))
+ 		fatal("No authentication or GSSAPI context");
+@@ -320,6 +324,9 @@ input_gssapi_mic(int type, u_int32_t plen, struct ssh *ssh)
+ 	sshbuf_free(b);
+ 	free(mic.value);
+ 
++	if (!authenticated)
++		auth_failure_delay(authctxt, tstart);
++
+ 	if ((!use_privsep || mm_is_monitor()) &&
+ 	    (displayname = ssh_gssapi_displayname()) != NULL)
+ 		auth2_record_info(authctxt, "%s", displayname);
+diff --git a/auth2.c b/auth2.c
+index 271789a77..18077d625 100644
+--- a/auth2.c
++++ b/auth2.c
+@@ -265,6 +265,12 @@ ensure_minimum_time_since(double start, double seconds)
+ 	nanosleep(&ts, NULL);
+ }
+ 
++void
++auth_failure_delay(Authctxt *authctxt, double tstart)
++{
++	ensure_minimum_time_since(tstart, user_specific_delay(authctxt->user));
++}
++
+ static int
+ input_userauth_request(int type, u_int32_t seq, struct ssh *ssh)
+ {
+@@ -348,8 +354,8 @@ input_userauth_request(int type, u_int32_t seq, struct ssh *ssh)
+ 		authenticated =	m->userauth(ssh, method);
+ 	}
+ 	if (!authctxt->authenticated && strcmp(method, "none") != 0)
+-		ensure_minimum_time_since(tstart,
+-		    user_specific_delay(authctxt->user));
++		auth_failure_delay(authctxt, tstart);
++
+ 	userauth_finish(ssh, authenticated, method, NULL);
+ 	r = 0;
+  out:
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 37f4dc20dd9..0d9d33c4597 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -41,6 +41,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
            file://CVE-2026-59997.patch \
            file://CVE-2026-59996.patch \
            file://CVE-2026-59995.patch \
+           file://CVE-2026-60001.patch \
            "
 SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 11/31] openssh: Fix CVE-2026-60002
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (9 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 10/31] openssh: Fix CVE-2026-60001 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 12/31] openssh: Fix CVE-2026-60000 Yoann Congal
                   ` (19 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Devansh Patel <devanshp@cisco.com>

This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-60002. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/openssh/openssh-portable/commit/e8bdfb151a356d0171fea4194dd205fbb252be23
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-60002

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../openssh/openssh/CVE-2026-60002.patch      | 226 ++++++++++++++++++
 .../openssh/openssh_9.6p1.bb                  |   1 +
 2 files changed, 227 insertions(+)
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch
new file mode 100644
index 00000000000..9e94e772618
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch
@@ -0,0 +1,226 @@
+From 767104acedd68c317b9d8fb603561e1a8be9e76a Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Mon, 6 Jul 2026 07:49:58 +0000
+Subject: [PATCH] upstream: fix ownership and lifetime of several bits of
+ client
+
+state that need to persist for the life of the connection, especially the
+cached hostkey that was being incorrectly freed early on some paths, possibly
+allowing its use after free.
+
+Reported by Zhenpeng (Leo) Lin from depthfirst.com
+
+CVE: CVE-2026-60002
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/e8bdfb151a356d0171fea4194dd205fbb252be23]
+
+Backport Changes:
+- Retained Scarthgap's valid_hostname() and valid_ruser() helpers when
+  relocating ssh_conn_info_free() from ssh.c to sshconnect.c.
+- Retained Scarthgap's ext-info-c proposal handling while applying the
+  upstream connection-state ownership and lifetime changes.
+- Retained the Scarthgap OpenBSD revision identifiers in ssh.c,
+  sshconnect.c, sshconnect.h, and sshconnect2.c.
+
+OpenBSD-Commit-ID: faaa6ad72e7d69d41fa8b197b606265b7d9bc73f
+(cherry picked from commit e8bdfb151a356d0171fea4194dd205fbb252be23)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ ssh.c         | 24 ++----------------------
+ sshconnect.c  | 47 +++++++++++++++++++++++++++++++++++++++++++++--
+ sshconnect.h  |  7 +++++--
+ sshconnect2.c | 20 +++++++++++---------
+ 4 files changed, 63 insertions(+), 35 deletions(-)
+
+diff --git a/ssh.c b/ssh.c
+index 9c49f98a8..aecdb79ea 100644
+--- a/ssh.c
++++ b/ssh.c
+@@ -606,26 +606,6 @@ set_addrinfo_port(struct addrinfo *addrs, int port)
+ 	}
+ }
+ 
+-static void
+-ssh_conn_info_free(struct ssh_conn_info *cinfo)
+-{
+-	if (cinfo == NULL)
+-		return;
+-	free(cinfo->conn_hash_hex);
+-	free(cinfo->shorthost);
+-	free(cinfo->uidstr);
+-	free(cinfo->keyalias);
+-	free(cinfo->thishost);
+-	free(cinfo->host_arg);
+-	free(cinfo->portstr);
+-	free(cinfo->remhost);
+-	free(cinfo->remuser);
+-	free(cinfo->homedir);
+-	free(cinfo->locuser);
+-	free(cinfo->jmphost);
+-	free(cinfo);
+-}
+-
+ static int
+ valid_hostname(const char *s)
+ {
+@@ -1771,8 +1751,8 @@ main(int ac, char **av)
+ 	ssh_signal(SIGCHLD, main_sigchld_handler);
+ 
+ 	/* Log into the remote system.  Never returns if the login fails. */
+-	ssh_login(ssh, &sensitive_data, host, (struct sockaddr *)&hostaddr,
+-	    options.port, pw, timeout_ms, cinfo);
++	ssh_login(ssh, &sensitive_data, host, &hostaddr, options.port,
++	    pw, timeout_ms, cinfo);
+ 
+ 	/* We no longer need the private host keys.  Clear them now. */
+ 	if (sensitive_data.nkeys != 0) {
+diff --git a/sshconnect.c b/sshconnect.c
+index bd077c75c..7823b6782 100644
+--- a/sshconnect.c
++++ b/sshconnect.c
+@@ -83,6 +83,49 @@ extern char *__progname;
+ static int show_other_keys(struct hostkeys *, struct sshkey *);
+ static void warn_changed_key(struct sshkey *);
+ 
++void
++ssh_conn_info_free(struct ssh_conn_info *cinfo)
++{
++	if (cinfo == NULL)
++		return;
++	free(cinfo->conn_hash_hex);
++	free(cinfo->shorthost);
++	free(cinfo->uidstr);
++	free(cinfo->keyalias);
++	free(cinfo->thishost);
++	free(cinfo->host_arg);
++	free(cinfo->portstr);
++	free(cinfo->remhost);
++	free(cinfo->remuser);
++	free(cinfo->homedir);
++	free(cinfo->locuser);
++	free(cinfo->jmphost);
++	freezero(cinfo, sizeof(*cinfo));
++}
++
++struct ssh_conn_info *
++ssh_conn_info_dup(const struct ssh_conn_info *cinfo)
++{
++	struct ssh_conn_info *ret;
++
++	if (cinfo == NULL)
++		return NULL;
++	ret = xcalloc(1, sizeof(*ret));
++	ret->conn_hash_hex = xstrdup(cinfo->conn_hash_hex);
++	ret->shorthost = xstrdup(cinfo->shorthost);
++	ret->uidstr = xstrdup(cinfo->uidstr);
++	ret->keyalias = xstrdup(cinfo->keyalias);
++	ret->thishost = xstrdup(cinfo->thishost);
++	ret->host_arg = xstrdup(cinfo->host_arg);
++	ret->portstr = xstrdup(cinfo->portstr);
++	ret->remhost = xstrdup(cinfo->remhost);
++	ret->remuser = xstrdup(cinfo->remuser);
++	ret->homedir = xstrdup(cinfo->homedir);
++	ret->locuser = xstrdup(cinfo->locuser);
++	ret->jmphost = xstrdup(cinfo->jmphost);
++	return ret;
++}
++
+ /* Expand a proxy command */
+ static char *
+ expand_proxy_command(const char *proxy_command, const char *user,
+@@ -1559,8 +1602,8 @@ out:
+  */
+ void
+ ssh_login(struct ssh *ssh, Sensitive *sensitive, const char *orighost,
+-    struct sockaddr *hostaddr, u_short port, struct passwd *pw, int timeout_ms,
+-    const struct ssh_conn_info *cinfo)
++    struct sockaddr_storage *hostaddr, u_short port, struct passwd *pw,
++    int timeout_ms, const struct ssh_conn_info *cinfo)
+ {
+ 	char *host;
+ 	char *server_user, *local_user;
+diff --git a/sshconnect.h b/sshconnect.h
+index 79d35cc19..da2a73f5a 100644
+--- a/sshconnect.h
++++ b/sshconnect.h
+@@ -71,7 +71,7 @@ int	 ssh_connect(struct ssh *, const char *, const char *,
+ void	 ssh_kill_proxy_command(void);
+ 
+ void	 ssh_login(struct ssh *, Sensitive *, const char *,
+-    struct sockaddr *, u_short, struct passwd *, int,
++    struct sockaddr_storage *, u_short, struct passwd *, int,
+     const struct ssh_conn_info *);
+ 
+ int	 verify_host_key(char *, struct sockaddr *, struct sshkey *,
+@@ -80,7 +80,7 @@ int	 verify_host_key(char *, struct sockaddr *, struct sshkey *,
+ void	 get_hostfile_hostname_ipaddr(char *, struct sockaddr *, u_short,
+     char **, char **);
+ 
+-void	 ssh_kex2(struct ssh *ssh, char *, struct sockaddr *, u_short,
++void	 ssh_kex2(struct ssh *ssh, char *, struct sockaddr_storage *, u_short,
+     const struct ssh_conn_info *);
+ 
+ void	 ssh_userauth2(struct ssh *ssh, const char *, const char *,
+@@ -94,3 +94,6 @@ void	 maybe_add_key_to_agent(const char *, struct sshkey *,
+ void	 load_hostkeys_command(struct hostkeys *, const char *,
+     const char *, const struct ssh_conn_info *,
+     const struct sshkey *, const char *);
++
++void ssh_conn_info_free(struct ssh_conn_info *);
++struct ssh_conn_info *ssh_conn_info_dup(const struct ssh_conn_info *);
+diff --git a/sshconnect2.c b/sshconnect2.c
+index a296c9b8c..9efb3da8a 100644
+--- a/sshconnect2.c
++++ b/sshconnect2.c
+@@ -89,7 +89,7 @@ extern Options options;
+  */
+ 
+ static char *xxx_host;
+-static struct sockaddr *xxx_hostaddr;
++static struct sockaddr_storage xxx_hostaddr;
+ static const struct ssh_conn_info *xxx_conn_info;
+ static int key_type_allowed(struct sshkey *, const char *);
+ 
+@@ -105,7 +105,7 @@ verify_host_key_callback(struct sshkey *hostkey, struct ssh *ssh)
+ 		fatal("Server host key %s not in HostKeyAlgorithms",
+ 		    sshkey_ssh_name(hostkey));
+ 	}
+-	if (verify_host_key(xxx_host, xxx_hostaddr, hostkey,
++	if (verify_host_key(xxx_host, (struct sockaddr *)&xxx_hostaddr, hostkey,
+ 	    xxx_conn_info) != 0)
+ 		fatal("Host key verification failed.");
+ 	return 0;
+@@ -222,16 +222,16 @@ order_hostkeyalgs(char *host, struct sockaddr *hostaddr, u_short port,
+ }
+ 
+ void
+-ssh_kex2(struct ssh *ssh, char *host, struct sockaddr *hostaddr, u_short port,
+-    const struct ssh_conn_info *cinfo)
++ssh_kex2(struct ssh *ssh, char *host, struct sockaddr_storage *hostaddr,
++    u_short port, const struct ssh_conn_info *cinfo)
+ {
+ 	char *myproposal[PROPOSAL_MAX];
+ 	char *s, *all_key, *hkalgs = NULL;
+ 	int r, use_known_hosts_order = 0;
+ 
+-	xxx_host = host;
+-	xxx_hostaddr = hostaddr;
+-	xxx_conn_info = cinfo;
++	xxx_host = xstrdup(host);
++	xxx_hostaddr = *hostaddr;
++	xxx_conn_info = ssh_conn_info_dup(cinfo);
+ 
+ 	if (options.rekey_limit || options.rekey_interval)
+ 		ssh_packet_set_rekey_limits(ssh, options.rekey_limit,
+@@ -257,8 +257,10 @@ ssh_kex2(struct ssh *ssh, char *host, struct sockaddr *hostaddr, u_short port,
+ 	if ((s = kex_names_cat(options.kex_algorithms, "ext-info-c")) == NULL)
+ 		fatal_f("kex_names_cat");
+ 
+-	if (use_known_hosts_order)
+-		hkalgs = order_hostkeyalgs(host, hostaddr, port, cinfo);
++	if (use_known_hosts_order) {
++		hkalgs = order_hostkeyalgs(host, (struct sockaddr *)hostaddr,
++		    port, cinfo);
++	}
+ 
+ 	kex_proposal_populate_entries(ssh, myproposal, s, options.ciphers,
+ 	    options.macs, compression_alg_list(options.compression),
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 0d9d33c4597..708399e8022 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -42,6 +42,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
            file://CVE-2026-59996.patch \
            file://CVE-2026-59995.patch \
            file://CVE-2026-60001.patch \
+           file://CVE-2026-60002.patch \
            "
 SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 12/31] openssh: Fix CVE-2026-60000
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (10 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 11/31] openssh: Fix CVE-2026-60002 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 13/31] cups: fix CVE-2026-27447 Yoann Congal
                   ` (18 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Devansh Patel <devanshp@cisco.com>

This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-60000. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-60000

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../openssh/openssh/CVE-2026-60000.patch      | 140 ++++++++++++++++++
 .../openssh/openssh_9.6p1.bb                  |   1 +
 2 files changed, 141 insertions(+)
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
new file mode 100644
index 00000000000..9c25786ced0
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
@@ -0,0 +1,140 @@
+From 055316632809a2e2e58eac2020699b52187d1b11 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Mon, 6 Jul 2026 07:53:30 +0000
+Subject: [PATCH] upstream: Fix multiple RFC 4462 (GSSAPIAuthentication)
+ compliance
+
+problems
+
+1) Remove an early failure return for GSSAPI authentication attempts
+made for invalid accounts that yielded different behaviour for
+valid vs invalid accounts.
+
+2) Fix a situation where some GSSAPI requestes were not correctly
+subjected to MaxAuthTries.
+
+3) Fix a moderate pre-authentication resource DoS related to #2.
+
+Add missing logging for error cases.
+
+Report and fixes from Manfred Kaiser, milCERT AT
+
+CVE: CVE-2026-60000
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192]
+
+Backport Changes:
+- Kept Scarthgap's PRIVSEP(ssh_gssapi_server_ctx()) interface and its
+  authentication-context guard while applying the upstream RFC 4462 state,
+  failure, logging, and MaxAuthTries changes.
+- Retained the Scarthgap auth2-gss.c OpenBSD revision identifier.
+
+OpenBSD-Commit-ID: ca0acdd64eea435d6f89534538a9eb404a5629d3
+(cherry picked from commit 5d04ca6af739b82fd30d84d2783ca802ebfa1192)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ auth2-gss.c | 53 ++++++++++++++++++++++++-----------------------------
+ 1 file changed, 24 insertions(+), 29 deletions(-)
+
+diff --git a/auth2-gss.c b/auth2-gss.c
+index 195578bcf..6846eae5b 100644
+--- a/auth2-gss.c
++++ b/auth2-gss.c
+@@ -110,12 +110,6 @@ userauth_gssapi(struct ssh *ssh, const char *method)
+ 		return (0);
+ 	}
+ 
+-	if (!authctxt->valid || authctxt->user == NULL) {
+-		debug2_f("disabled because of invalid user");
+-		free(doid);
+-		return (0);
+-	}
+-
+ 	if (GSS_ERROR(PRIVSEP(ssh_gssapi_server_ctx(&ctxt, &goid)))) {
+ 		if (ctxt != NULL)
+ 			ssh_gssapi_delete_ctx(&ctxt);
+@@ -177,8 +171,14 @@ input_gssapi_token(int type, u_int32_t plen, struct ssh *ssh)
+ 			    (r = sshpkt_send(ssh)) != 0)
+ 				fatal_fr(r, "send ERRTOK packet");
+ 		}
++		logit("Failed gssapi-with-mic for %s%.100s "
++		    "from %.200s port %d ssh2",
++		    authctxt->valid ? "" : "invalid user ",
++		    authctxt->user,
++		    ssh_remote_ipaddr(ssh), ssh_remote_port(ssh));
+ 		authctxt->postponed = 0;
+ 		ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
++		ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL);
+ 		userauth_finish(ssh, 0, "gssapi-with-mic", NULL);
+ 	} else {
+ 		if (send_tok.length != 0) {
+@@ -190,14 +190,18 @@ input_gssapi_token(int type, u_int32_t plen, struct ssh *ssh)
+ 				fatal_fr(r, "send TOKEN packet");
+ 		}
+ 		if (maj_status == GSS_S_COMPLETE) {
+-			ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
+-			if (flags & GSS_C_INTEG_FLAG)
+-				ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC,
++			ssh_dispatch_set(ssh,
++			    SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
++			/* note: keep ERRTOK handler as per RFC 4462 s3.4 */
++			if (flags & GSS_C_INTEG_FLAG) {
++				ssh_dispatch_set(ssh,
++				    SSH2_MSG_USERAUTH_GSSAPI_MIC,
+ 				    &input_gssapi_mic);
+-			else
++			} else {
+ 				ssh_dispatch_set(ssh,
+ 				    SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE,
+ 				    &input_gssapi_exchange_complete);
++			}
+ 		}
+ 	}
+ 
+@@ -209,10 +213,6 @@ static int
+ input_gssapi_errtok(int type, u_int32_t plen, struct ssh *ssh)
+ {
+ 	Authctxt *authctxt = ssh->authctxt;
+-	Gssctxt *gssctxt;
+-	gss_buffer_desc send_tok = GSS_C_EMPTY_BUFFER;
+-	gss_buffer_desc recv_tok;
+-	OM_uint32 maj_status;
+ 	int r;
+ 	u_char *p;
+ 	size_t len;
+@@ -220,26 +220,21 @@ input_gssapi_errtok(int type, u_int32_t plen, struct ssh *ssh)
+ 	if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep))
+ 		fatal("No authentication or GSSAPI context");
+ 
+-	gssctxt = authctxt->methoddata;
+-	if ((r = sshpkt_get_string(ssh, &p, &len)) != 0 ||
++	/* Minimal error handling - just cancel auth and return FAILURE */
++	if ((r = sshpkt_get_string_direct(ssh, NULL, NULL)) != 0 ||
+ 	    (r = sshpkt_get_end(ssh)) != 0)
+ 		fatal_fr(r, "parse packet");
+-	recv_tok.value = p;
+-	recv_tok.length = len;
+-
+-	/* Push the error token into GSSAPI to see what it says */
+-	maj_status = PRIVSEP(ssh_gssapi_accept_ctx(gssctxt, &recv_tok,
+-	    &send_tok, NULL));
+-
+-	free(recv_tok.value);
+ 
+-	/* We can't return anything to the client, even if we wanted to */
++	logit("Failed gssapi-with-mic for %s%.100s from %.200s port %d ssh2",
++	    authctxt->valid ? "" : "invalid user ",
++	    authctxt->user,
++	    ssh_remote_ipaddr(ssh), ssh_remote_port(ssh));
++	authctxt->postponed = 0;
+ 	ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
+ 	ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL);
+-
+-	/* The client will have already moved on to the next auth */
+-
+-	gss_release_buffer(&maj_status, &send_tok);
++	ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC, NULL);
++	ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE, NULL);
++	userauth_finish(ssh, 0, "gssapi-with-mic", NULL);
+ 	return 0;
+ }
+ 
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 708399e8022..ba8aaad9bbb 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -43,6 +43,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
            file://CVE-2026-59995.patch \
            file://CVE-2026-60001.patch \
            file://CVE-2026-60002.patch \
+           file://CVE-2026-60000.patch \
            "
 SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 13/31] cups: fix CVE-2026-27447
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (11 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 12/31] openssh: Fix CVE-2026-60000 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 14/31] cups: fix CVE-2026-41079 Yoann Congal
                   ` (17 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

Pick the upstream backport [1] for CVE-2026-27447 as mentioned in [2], where
the scheduler treated local user and group names as case-insensitive.

Also include the two upstream regression fixes that followed the CVE
fix:
- CVE-2026-27447-regression_p1.patch [3] fixes a cupsd crash when the
  referenced user does not exist on the server. This regression was
  reported in OpenPrinting/cups Issue [5].
- CVE-2026-27447-regression_p2.patch [4] fixes unauthenticated print
  policies for non-local accounts. This regression was reported in
  OpenPrinting/cups Issue [6].

[1] https://github.com/OpenPrinting/cups/commit/a0c62c1e69604ff061089b750073199fab5a1beb
[2] https://security-tracker.debian.org/tracker/CVE-2026-27447
[3] https://github.com/OpenPrinting/cups/commit/6d97ee39fedf12a7a5429a74f4156ef9bb67f562
[4] https://github.com/OpenPrinting/cups/commit/849fba7d7a1144e48d45c5e6ba2504765912ece0
[5] https://github.com/OpenPrinting/cups/issues/1555
[6] https://github.com/OpenPrinting/cups/issues/1557

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-extended/cups/cups.inc           |   3 +
 .../cups/CVE-2026-27447-regression_p1.patch   |  33 ++++++
 .../cups/CVE-2026-27447-regression_p2.patch   |  46 ++++++++
 .../cups/cups/CVE-2026-27447.patch            | 108 ++++++++++++++++++
 4 files changed, 190 insertions(+)
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447.patch

diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index c7475d2b813..ec9392b73dd 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -20,6 +20,9 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
            file://CVE-2025-58436.patch \
            file://CVE-2025-61915.patch \
            file://0001-conf.c-Fix-stopping-scheduler-on-unknown-directive.patch \
+           file://CVE-2026-27447.patch \
+           file://CVE-2026-27447-regression_p1.patch \
+           file://CVE-2026-27447-regression_p2.patch \
            "
 
 GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch
new file mode 100644
index 00000000000..d581ee36fdf
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch
@@ -0,0 +1,33 @@
+From 6d97ee39fedf12a7a5429a74f4156ef9bb67f562 Mon Sep 17 00:00:00 2001
+From: Zdenek Dohnal <zdohnal@redhat.com>
+Date: Wed, 22 Apr 2026 12:40:14 +0200
+Subject: [PATCH] Fix cupsd crash if user does not exist on server
+
+CVE: CVE-2026-27447
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/6d97ee39fedf12a7a5429a74f4156ef9bb67f562]
+
+Backport Changes:
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+  carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 6d97ee39fedf12a7a5429a74f4156ef9bb67f562)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/auth.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/scheduler/auth.c b/scheduler/auth.c
+index 1678a29..4798e86 100644
+--- a/scheduler/auth.c
++++ b/scheduler/auth.c
+@@ -1810,7 +1810,7 @@ cupsdIsAuthorized(cupsd_client_t *con,	/* I - Connection */
+ 	 name;
+ 	 name = (char *)cupsArrayNext(best->names))
+     {
+-      if (!_cups_strcasecmp(name, "@OWNER") && owner &&
++      if (!_cups_strcasecmp(name, "@OWNER") && owner && pw &&
+           !strcmp(pw->pw_name, ownername))
+ 	return (HTTP_OK);
+       else if (!_cups_strcasecmp(name, "@SYSTEM"))
+-- 
+2.43.7
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch
new file mode 100644
index 00000000000..e46db92c760
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch
@@ -0,0 +1,46 @@
+From 849fba7d7a1144e48d45c5e6ba2504765912ece0 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Fri, 24 Apr 2026 14:06:06 -0400
+Subject: [PATCH] Fix unauthenticated print policies (Issue #1557)
+
+CVE: CVE-2026-27447
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/849fba7d7a1144e48d45c5e6ba2504765912ece0]
+
+Backport Changes:
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+  carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 849fba7d7a1144e48d45c5e6ba2504765912ece0)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/auth.c | 7 +++++--
+ 1 file changed, 5 insertions(+), 2 deletions(-)
+
+diff --git a/scheduler/auth.c b/scheduler/auth.c
+index 4798e86..1dd520d 100644
+--- a/scheduler/auth.c
++++ b/scheduler/auth.c
+@@ -1810,8 +1810,9 @@ cupsdIsAuthorized(cupsd_client_t *con,	/* I - Connection */
+ 	 name;
+ 	 name = (char *)cupsArrayNext(best->names))
+     {
+-      if (!_cups_strcasecmp(name, "@OWNER") && owner && pw &&
+-          !strcmp(pw->pw_name, ownername))
++      if (!_cups_strcasecmp(name, "@OWNER") && owner &&
++          ((pw && !strcmp(pw->pw_name, ownername)) ||
++           (!pw && type == CUPSD_AUTH_NONE && !_cups_strcasecmp(username, ownername))))
+ 	return (HTTP_OK);
+       else if (!_cups_strcasecmp(name, "@SYSTEM"))
+       {
+@@ -1825,6 +1826,8 @@ cupsdIsAuthorized(cupsd_client_t *con,	/* I - Connection */
+       }
+       else if (pw && !strcmp(pw->pw_name, name))
+         return (HTTP_OK);
++      else if (!pw && type == CUPSD_AUTH_NONE && !_cups_strcasecmp(username, name))
++	return (HTTP_STATUS_OK);
+     }
+ 
+     for (name = (char *)cupsArrayFirst(best->names);
+-- 
+2.43.7
+
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447.patch
new file mode 100644
index 00000000000..1614faa7f17
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-27447.patch
@@ -0,0 +1,108 @@
+From 37b8a4387864eded1a15a45db8950a23e5c610d2 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 31 Mar 2026 14:04:21 -0400
+Subject: [PATCH] CVE-2026-27447: The scheduler treated local user and group
+ names as case-insensitive.
+
+CVE: CVE-2026-27447
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/a0c62c1e69604ff061089b750073199fab5a1beb]
+
+Backport Changes:
+- Rebase scheduler/auth.c context to the CUPS 2.4.11 source carried by this
+  recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+  carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit a0c62c1e69604ff061089b750073199fab5a1beb)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/auth.c | 31 +++++++++++++++----------------
+ 1 file changed, 15 insertions(+), 16 deletions(-)
+
+diff --git a/scheduler/auth.c b/scheduler/auth.c
+index d0430b4..1678a29 100644
+--- a/scheduler/auth.c
++++ b/scheduler/auth.c
+@@ -1,7 +1,7 @@
+ /*
+  * Authorization routines for the CUPS scheduler.
+  *
+- * Copyright © 2020-2024 by OpenPrinting.
++ * Copyright © 2020-2026 by OpenPrinting.
+  * Copyright © 2007-2019 by Apple Inc.
+  * Copyright © 1997-2007 by Easy Software Products, all rights reserved.
+  *
+@@ -1159,7 +1159,7 @@ cupsdCheckGroup(
+   group = getgrnam(groupname);
+   endgrent();
+ 
+-  if (group != NULL)
++  if (user && group)
+   {
+    /*
+     * Group exists, check it...
+@@ -1173,7 +1173,7 @@ cupsdCheckGroup(
+       * User appears in the group membership...
+       */
+ 
+-      if (!_cups_strcasecmp(username, group->gr_mem[i]))
++      if (!strcmp(user->pw_name, group->gr_mem[i]))
+ 	return (1);
+     }
+ 
+@@ -1184,25 +1184,24 @@ cupsdCheckGroup(
+     * belongs to...
+     */
+ 
+-    if (user)
+-    {
+-      int	ngroups;		/* Number of groups */
++    int		ngroups;		/* Number of groups */
+ #  ifdef __APPLE__
+-      int	groups[2048];		/* Groups that user belongs to */
++    int		groups[2048];		/* Groups that user belongs to */
+ #  else
+-      gid_t	groups[2048];		/* Groups that user belongs to */
++    gid_t	groups[2048];		/* Groups that user belongs to */
+ #  endif /* __APPLE__ */
+ 
+-      ngroups = (int)(sizeof(groups) / sizeof(groups[0]));
++    ngroups = (int)(sizeof(groups) / sizeof(groups[0]));
+ #  ifdef __APPLE__
+-      getgrouplist(username, (int)user->pw_gid, groups, &ngroups);
++    getgrouplist(user->pw_name, (int)user->pw_gid, groups, &ngroups);
+ #  else
+-      getgrouplist(username, user->pw_gid, groups, &ngroups);
++    getgrouplist(user->pw_name, user->pw_gid, groups, &ngroups);
+ #endif /* __APPLE__ */
+ 
+-      for (i = 0; i < ngroups; i ++)
+-        if ((int)groupid == (int)groups[i])
+-	  return (1);
++    for (i = 0; i < ngroups; i ++)
++    {
++      if ((int)groupid == (int)groups[i])
++	return (1);
+     }
+ #endif /* HAVE_GETGROUPLIST */
+   }
+@@ -1812,7 +1811,7 @@ cupsdIsAuthorized(cupsd_client_t *con,	/* I - Connection */
+ 	 name = (char *)cupsArrayNext(best->names))
+     {
+       if (!_cups_strcasecmp(name, "@OWNER") && owner &&
+-          !_cups_strcasecmp(username, ownername))
++          !strcmp(pw->pw_name, ownername))
+ 	return (HTTP_OK);
+       else if (!_cups_strcasecmp(name, "@SYSTEM"))
+       {
+@@ -1824,7 +1823,7 @@ cupsdIsAuthorized(cupsd_client_t *con,	/* I - Connection */
+         if (cupsdCheckGroup(username, pw, name + 1))
+           return (HTTP_OK);
+       }
+-      else if (!_cups_strcasecmp(username, name))
++      else if (pw && !strcmp(pw->pw_name, name))
+         return (HTTP_OK);
+     }
+ 
+-- 
+2.43.7


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 14/31] cups: fix CVE-2026-41079
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (12 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 13/31] cups: fix CVE-2026-27447 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 15/31] cups: fix CVE-2026-34978 Yoann Congal
                   ` (16 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

Pick the upstream fix [1] for CVE-2026-41079 as referenced by Debian [2].

[1] https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080
[2] https://security-tracker.debian.org/tracker/CVE-2026-41079

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
[YC: reverted modified indentation in imported patch]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-extended/cups/cups.inc           |  1 +
 .../cups/cups/CVE-2026-41079.patch            | 71 +++++++++++++++++++
 2 files changed, 72 insertions(+)
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-41079.patch

diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index ec9392b73dd..f74bcaffab5 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -23,6 +23,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
            file://CVE-2026-27447.patch \
            file://CVE-2026-27447-regression_p1.patch \
            file://CVE-2026-27447-regression_p2.patch \
+           file://CVE-2026-41079.patch \
            "
 
 GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-41079.patch b/meta/recipes-extended/cups/cups/CVE-2026-41079.patch
new file mode 100644
index 00000000000..87a7e42316b
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-41079.patch
@@ -0,0 +1,71 @@
+From a331e93e2f9baf411715ef69ae19b73827da23d7 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Mon, 13 Apr 2026 11:50:23 -0400
+Subject: [PATCH] Limit num_bytes for SNMP string values.
+
+CVE: CVE-2026-41079
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080]
+
+(cherry picked from commit b7c2525a885f528d243c3a92197ca99609b3f080)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ cups/snmp-private.h | 6 +++---
+ cups/snmp.c         | 8 ++++++--
+ 2 files changed, 9 insertions(+), 5 deletions(-)
+
+diff --git a/cups/snmp-private.h b/cups/snmp-private.h
+index 52b8740..015f53e 100644
+--- a/cups/snmp-private.h
++++ b/cups/snmp-private.h
+@@ -1,7 +1,7 @@
+ /*
+  * Private SNMP definitions for CUPS.
+  *
+- * Copyright © 2020-2024 by OpenPrinting.
++ * Copyright © 2020-2026 by OpenPrinting.
+  * Copyright © 2007-2014 by Apple Inc.
+  * Copyright © 2006-2007 by Easy Software Products, all rights reserved.
+  *
+@@ -58,9 +58,9 @@ typedef enum cups_asn1_e cups_asn1_t;	/**** ASN1 request/object types ****/
+ 
+ typedef struct cups_snmp_string_s	/**** String value ****/
+ {
+-  unsigned char	bytes[CUPS_SNMP_MAX_STRING];
+-					/* Bytes in string */
+   unsigned	num_bytes;		/* Number of bytes */
++  unsigned char	bytes[CUPS_SNMP_MAX_STRING + 1];
++					/* Bytes in string */
+ } cups_snmp_string_t;
+ 
+ union cups_snmp_value_u			/**** Object value ****/
+diff --git a/cups/snmp.c b/cups/snmp.c
+index 54e348f..2fcb38d 100644
+--- a/cups/snmp.c
++++ b/cups/snmp.c
+@@ -1,7 +1,7 @@
+ /*
+  * SNMP functions for CUPS.
+  *
+- * Copyright © 2020-2024 by OpenPrinting.
++ * Copyright © 2020-2026 by OpenPrinting.
+  * Copyright © 2007-2019 by Apple Inc.
+  * Copyright © 2006-2007 by Easy Software Products, all rights reserved.
+  *
+@@ -1042,10 +1042,14 @@ asn1_decode_snmp(unsigned char *buffer,	/* I - Buffer */
+ 	        case CUPS_ASN1_OCTET_STRING :
+ 	        case CUPS_ASN1_BIT_STRING :
+ 	        case CUPS_ASN1_HEX_STRING :
+-		    packet->object_value.string.num_bytes = length;
+ 		    asn1_get_string(&bufptr, bufend, length,
+ 		                    (char *)packet->object_value.string.bytes,
+ 				    sizeof(packet->object_value.string.bytes));
++
++                    if (length >= sizeof(packet->object_value.string.bytes))
++		      packet->object_value.string.num_bytes = sizeof(packet->object_value.string.bytes) - 1;
++                    else
++		      packet->object_value.string.num_bytes = length;
+ 	            break;
+ 
+ 	        case CUPS_ASN1_OID :
+-- 
+2.43.7


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 15/31] cups: fix CVE-2026-34978
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (13 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 14/31] cups: fix CVE-2026-41079 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 16/31] cups: fix CVE-2026-34980 Yoann Congal
                   ` (15 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

Pick the upstream patch [1] as mentioned in [2].

[1] https://github.com/OpenPrinting/cups/commit/730347c5bbd5e1271149c6739aa858c0c83a7568
[2] https://security-tracker.debian.org/tracker/CVE-2026-34978

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
[YC: reverted upstream patch indentation]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-extended/cups/cups.inc           |   1 +
 .../cups/cups/CVE-2026-34978.patch            | 107 ++++++++++++++++++
 2 files changed, 108 insertions(+)
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34978.patch

diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index f74bcaffab5..5e272dbcf6b 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -24,6 +24,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
            file://CVE-2026-27447-regression_p1.patch \
            file://CVE-2026-27447-regression_p2.patch \
            file://CVE-2026-41079.patch \
+           file://CVE-2026-34978.patch \
            "
 
 GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34978.patch b/meta/recipes-extended/cups/cups/CVE-2026-34978.patch
new file mode 100644
index 00000000000..5929268f4fa
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34978.patch
@@ -0,0 +1,107 @@
+From ab6ab965de6890aed4df39c97f7cd708fd5cb00c Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 31 Mar 2026 14:18:26 -0400
+Subject: [PATCH] Fix RSS notifier.
+
+CVE: CVE-2026-34978
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/730347c5bbd5e1271149c6739aa858c0c83a7568]
+
+Backport Changes:
+- Rebase scheduler/ipp.c subscription context to the CUPS 2.4.11 source
+  carried by this recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+  carries the CVE details and the target source release-note sections differ.
+- Omit the upstream scheduler/ipp.c copyright-year-only header update because
+  this backport carries only the functional changes needed for CUPS 2.4.11.
+
+(cherry picked from commit 730347c5bbd5e1271149c6739aa858c0c83a7568)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ notifier/rss.c  |   20 ++++++++++++++------
+ scheduler/ipp.c |   12 ++++++++++++
+ 2 files changed, 26 insertions(+), 6 deletions(-)
+
+diff --git a/notifier/rss.c b/notifier/rss.c
+index f17e1494c..250ad877e 100644
+--- a/notifier/rss.c
++++ b/notifier/rss.c
+@@ -1,11 +1,12 @@
+ /*
+  * RSS notifier for CUPS.
+  *
+- * Copyright © 2020-2024 by OpenPrinting.
+- * Copyright 2007-2015 by Apple Inc.
+- * Copyright 2007 by Easy Software Products.
++ * Copyright © 2020-2026 by OpenPrinting.
++ * Copyright © 2007-2015 by Apple Inc.
++ * Copyright © 2007 by Easy Software Products.
+  *
+- * Licensed under Apache License v2.0.  See the file "LICENSE" for more information.
++ * Licensed under Apache License v2.0.  See the file "LICENSE" for more
++ * information.
+  */
+ 
+ /*
+@@ -80,6 +81,7 @@ main(int  argc,				/* I - Number of command-line arguments */
+   http_status_t	status;			/* HTTP GET/PUT status code */
+   char		filename[1024],		/* Local filename */
+ 		newname[1024];		/* filename.N */
++  struct stat	fileinfo;		/* Local file information */
+   cups_lang_t	*language;		/* Language information */
+   ipp_attribute_t *printer_up_time,	/* Timestamp on event */
+ 		*notify_sequence_number,/* Sequence number */
+@@ -111,9 +113,9 @@ main(int  argc,				/* I - Number of command-line arguments */
+ 
+   if (httpSeparateURI(HTTP_URI_CODING_ALL, argv[1], scheme, sizeof(scheme),
+                       username, sizeof(username), host, sizeof(host), &port,
+-		      resource, sizeof(resource)) < HTTP_URI_OK)
++		      resource, sizeof(resource)) < HTTP_URI_OK || strstr(resource, "../") != NULL)
+   {
+-    fprintf(stderr, "ERROR: Bad RSS URI \"%s\"!\n", argv[1]);
++    fprintf(stderr, "ERROR: Bad RSS URI \"%s\".\n", argv[1]);
+     return (1);
+   }
+ 
+@@ -209,6 +211,12 @@ main(int  argc,				/* I - Number of command-line arguments */
+     snprintf(filename, sizeof(filename), "%s/rss%s", cachedir, resource);
+     snprintf(newname, sizeof(newname), "%s.N", filename);
+ 
++    if (!lstat(filename, &fileinfo) && !S_ISREG(fileinfo.st_mode))
++    {
++      fprintf(stderr, "ERROR: Local RSS path \"%s\" is not a file.\n", filename);
++      return (1);
++    }
++
+     httpAssembleURIf(HTTP_URI_CODING_ALL, baseurl, sizeof(baseurl), "http",
+                      NULL, server_name, atoi(server_port), "/rss%s", resource);
+   }
+diff --git a/scheduler/ipp.c b/scheduler/ipp.c
+index 2d80a960e..2dc7376c1 100644
+--- a/scheduler/ipp.c
++++ b/scheduler/ipp.c
+@@ -1985,6 +1985,12 @@ add_job_subscriptions(
+ 	                "notify-status-code", IPP_ATTRIBUTES);
+ 	  return;
+ 	}
++	else if (!strcmp(scheme, "rss") && strstr(resource, "../") != NULL)
++	{
++          send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad notify-recipient-uri URI \"%s\"."), recipient);
++	  ippAddInteger(con->response, IPP_TAG_SUBSCRIPTION, IPP_TAG_ENUM, "notify-status-code", IPP_STATUS_ERROR_ATTRIBUTES_OR_VALUES);
++	  return;
++	}
+       }
+       else if (!strcmp(attr->name, "notify-pull-method") &&
+                attr->value_tag == IPP_TAG_KEYWORD)
+@@ -6010,6 +6016,12 @@ create_subscriptions(
+ 	                "notify-status-code", IPP_ATTRIBUTES);
+ 	  return;
+ 	}
++	else if (!strcmp(scheme, "rss") && strstr(resource, "../") != NULL)
++	{
++	  send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad notify-recipient-uri URI \"%s\"."), recipient);
++	  ippAddInteger(con->response, IPP_TAG_SUBSCRIPTION, IPP_TAG_ENUM, "notify-status-code", IPP_STATUS_ERROR_ATTRIBUTES_OR_VALUES);
++	  return;
++	}
+       }
+       else if (!strcmp(attr->name, "notify-pull-method") &&
+                attr->value_tag == IPP_TAG_KEYWORD)


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 16/31] cups: fix CVE-2026-34980
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (14 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 15/31] cups: fix CVE-2026-34978 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 17/31] cups: fix CVE-2026-34979 Yoann Congal
                   ` (14 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

Pick the upstream fix [1] for CVE-2026-34980 as mentioned in [2], where
the scheduler did not filter control characters from option values.

Also include the upstream regression fixes that followed the CVE fix:

- CVE-2026-34980-regression_p1.patch [3] fixes filter PPD keyword
  processing. The CVE fix parsed PPD keywords into a temporary array,
  but the loop did not advance the keyword pointer. This regression was
  reported in OpenPrinting/cups Issue [4].
- CVE-2026-34980-regression_p2.patch [5] fixes a get_options() regression
  where the option-value parser did not advance the input pointer for
  whitespace/control-character paths.

[1] https://github.com/OpenPrinting/cups/commit/8d0f51cac24cb5bf949c5b6a221e51a150d982e3
[2] https://security-tracker.debian.org/tracker/CVE-2026-34980
[3] https://github.com/OpenPrinting/cups/commit/3f2bdc293243bca938c6de23ba50e6d783189629
[4] https://github.com/OpenPrinting/cups/issues/1562
[5] https://github.com/OpenPrinting/cups/commit/da0ff58c041f7ee129c3c2c72fb14df1f1e4069a

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-extended/cups/cups.inc           |  3 +
 .../cups/CVE-2026-34980-regression_p1.patch   | 31 +++++++
 .../cups/CVE-2026-34980-regression_p2.patch   | 75 ++++++++++++++++
 .../cups/cups/CVE-2026-34980.patch            | 85 +++++++++++++++++++
 4 files changed, 194 insertions(+)
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980.patch

diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index 5e272dbcf6b..7a8b845953c 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -25,6 +25,9 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
            file://CVE-2026-27447-regression_p2.patch \
            file://CVE-2026-41079.patch \
            file://CVE-2026-34978.patch \
+           file://CVE-2026-34980.patch \
+           file://CVE-2026-34980-regression_p1.patch \
+           file://CVE-2026-34980-regression_p2.patch \
            "
 
 GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch
new file mode 100644
index 00000000000..483d695a93a
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch
@@ -0,0 +1,31 @@
+From 3f2bdc293243bca938c6de23ba50e6d783189629 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 28 Apr 2026 17:42:41 -0400
+Subject: [PATCH] Fix filter PPD keyword processing (Issue #1562)
+
+CVE: CVE-2026-34980
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/3f2bdc293243bca938c6de23ba50e6d783189629]
+
+(cherry picked from commit 3f2bdc293243bca938c6de23ba50e6d783189629)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/job.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/scheduler/job.c b/scheduler/job.c
+index 895b2d9..915ba94 100644
+--- a/scheduler/job.c
++++ b/scheduler/job.c
+@@ -5419,7 +5419,7 @@ update_job(cupsd_job_t *job)		/* I - Job to check */
+       keywords     = NULL;
+       num_keywords = cupsParseOptions(message, 0, &keywords);
+ 
+-      for (i = 0, keyword = keywords; i < num_keywords; i ++)
++      for (i = 0, keyword = keywords; i < num_keywords; i ++, keyword ++)
+       {
+        /*
+         * Filter out "special" PPD keywords...
+-- 
+2.43.7
+
+
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch
new file mode 100644
index 00000000000..739938c9a59
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch
@@ -0,0 +1,75 @@
+From da0ff58c041f7ee129c3c2c72fb14df1f1e4069a Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Wed, 8 Apr 2026 16:42:48 -0400
+Subject: [PATCH] Fix get_options regression (Issue #1532)
+
+CVE: CVE-2026-34980
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/da0ff58c041f7ee129c3c2c72fb14df1f1e4069a]
+
+(cherry picked from commit da0ff58c041f7ee129c3c2c72fb14df1f1e4069a)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/job.c |  4 ++--
+ test/5.5-lp.sh  | 10 +++++-----
+ 2 files changed, 7 insertions(+), 7 deletions(-)
+
+diff --git a/scheduler/job.c b/scheduler/job.c
+index 6b9d366..cf019e1 100644
+--- a/scheduler/job.c
++++ b/scheduler/job.c
+@@ -4144,7 +4144,7 @@ get_options(cupsd_job_t *job,		/* I - Job */
+ 	  case IPP_TAG_CHARSET :
+ 	  case IPP_TAG_LANGUAGE :
+ 	  case IPP_TAG_URI :
+-	      for (valptr = attr->values[i].string.text; *valptr;)
++	      for (valptr = attr->values[i].string.text; *valptr; valptr ++)
+ 	      {
+ 	       /*
+ 	        * Convert tabs and newlines to spaces, filter out control chars,
+@@ -4159,7 +4159,7 @@ get_options(cupsd_job_t *job,		/* I - Job */
+ 	        {
+ 	          if (strchr("\\\'\"", *valptr))
+ 		    *optptr++ = '\\';
+-		  *optptr++ = *valptr++;
++		  *optptr++ = *valptr;
+ 		}
+ 	      }
+ 
+diff --git a/test/5.5-lp.sh b/test/5.5-lp.sh
+index 25e9d65..fe60890 100644
+--- a/test/5.5-lp.sh
++++ b/test/5.5-lp.sh
+@@ -2,7 +2,7 @@
+ #
+ # Test the lp command.
+ #
+-# Copyright © 2020-2024 by OpenPrinting.
++# Copyright © 2020-2026 by OpenPrinting.
+ # Copyright © 2007-2019 by Apple Inc.
+ # Copyright © 1997-2005 by Easy Software Products, all rights reserved.
+ #
+@@ -72,8 +72,8 @@ echo ""
+ 
+ echo "LP Flood Test ($1 times in parallel)"
+ echo ""
+-echo "    lp -d Test1 testfile.jpg"
+-echo "    lp -d Test2 testfile.jpg"
++echo "    lp -d Test1 -t 'Flood Test N' testfile.jpg"
++echo "    lp -d Test2 -t 'Flood Test N' testfile.jpg"
+ i=0
+ pids=""
+ while test $i -lt $1; do
+@@ -83,9 +83,9 @@ while test $i -lt $1; do
+ 		j=`expr $j + 1`
+ 	done
+ 
+-	$runcups $VALGRIND ../systemv/lp -d Test1 ../examples/testfile.jpg 2>&1 &
++	$runcups $VALGRIND ../systemv/lp -d Test1 -t "Flood Test $j" ../examples/testfile.jpg 2>&1 &
+ 	pids="$pids $!"
+-	$runcups $VALGRIND ../systemv/lp -d Test2 ../examples/testfile.jpg 2>&1 &
++	$runcups $VALGRIND ../systemv/lp -d Test2 -t "Flood Test $j" ../examples/testfile.jpg 2>&1 &
+ 	pids="$pids $!"
+ 
+ 	i=`expr $i + 1`
+-- 
+2.43.7
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980.patch
new file mode 100644
index 00000000000..c38cc2c9e38
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34980.patch
@@ -0,0 +1,85 @@
+From e206c7643a7574cab2e9457eac4c9f755dbf44ff Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 31 Mar 2026 14:45:13 -0400
+Subject: [PATCH] Filter out control characters from option values.
+
+CVE: CVE-2026-34980
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/8d0f51cac24cb5bf949c5b6a221e51a150d982e3]
+
+Backport Changes:
+- Rebase scheduler/job.c option-handling context to the CUPS 2.4.11
+  source carried by this recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+  carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 8d0f51cac24cb5bf949c5b6a221e51a150d982e3)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/job.c |   41 +++++++++++++++++++++++++++++++++++------
+ 1 file changed, 35 insertions(+), 6 deletions(-)
+
+diff --git a/scheduler/job.c b/scheduler/job.c
+index 822a247..895b2d9 100644
+--- a/scheduler/job.c
++++ b/scheduler/job.c
+@@ -4121,9 +4121,21 @@ get_options(cupsd_job_t *job,		/* I - Job */
+ 	  case IPP_TAG_URI :
+ 	      for (valptr = attr->values[i].string.text; *valptr;)
+ 	      {
+-	        if (strchr(" \t\n\\\'\"", *valptr))
+-		  *optptr++ = '\\';
+-		*optptr++ = *valptr++;
++	       /*
++	        * Convert tabs and newlines to spaces, filter out control chars,
++	        * and escape \, ', and ".
++	        */
++
++	        if (isspace(*valptr & 255))
++	        {
++	          *optptr++ = ' ';
++	        }
++	        else if ((*valptr & 255) >= ' ' && *valptr != 0x7f)
++	        {
++	          if (strchr("\\\'\"", *valptr))
++		    *optptr++ = '\\';
++		  *optptr++ = *valptr++;
++		}
+ 	      }
+ 
+ 	      *optptr = '\0';
+@@ -5394,13 +5409,30 @@ update_job(cupsd_job_t *job)		/* I - Job to check */
+     else if (loglevel == CUPSD_LOG_PPD)
+     {
+      /*
+-      * Set attribute(s)...
++      * Set PPD keyword(s)/value(s)...
+       */
+ 
++      int		i,		/* Looping var */
++			num_keywords;	/* Number of keywords */
++      cups_option_t	*keywords,	/* Keywords */
++			*keyword;	/* Current keyword */
++
+       cupsdLogJob(job, CUPSD_LOG_DEBUG, "PPD: %s", message);
+ 
+-      job->num_keywords = cupsParseOptions(message, job->num_keywords,
+-                                           &job->keywords);
++      keywords     = NULL;
++      num_keywords = cupsParseOptions(message, 0, &keywords);
++
++      for (i = 0, keyword = keywords; i < num_keywords; i ++)
++      {
++       /*
++        * Filter out "special" PPD keywords...
++        */
++
++        if (strcmp(keyword->name, "cupsFilter") && strcmp(keyword->name, "cupsFilter2") && strcmp(keyword->name, "cupsFinishingTemplate") && strcmp(keyword->name, "cupsIPPFinishings") && strcmp(keyword->name, "cupsIPPReason") && strcmp(keyword->name, "cupsMarkerName") && strcmp(keyword->name, "cupsMaxSize") && strncmp(keyword->name, "cupsMediaQualifier", 18) && strcmp(keyword->name, "cupsMinSize") && strcmp(keyword->name, "cupsPageSizeCategory") && strcmp(keyword->name, "cupsPortMonitor") && strcmp(keyword->name, "cupsPreFilter") && strcmp(keyword->name, "cupsPrintQuality") && strcmp(keyword->name, "APPrinterPreset"))
++          job->num_keywords = cupsAddOption(keyword->name, keyword->value, job->num_keywords, &job->keywords);
++      }
++
++      cupsFreeOptions(num_keywords, keywords);
+     }
+     else
+     {
+-- 
+2.43.7


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 17/31] cups: fix CVE-2026-34979
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (15 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 16/31] cups: fix CVE-2026-34980 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 18/31] cups: fix CVE-2026-34990 Yoann Congal
                   ` (13 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

Pick the upstream patch [1] as mentioned in [2].

[1] https://github.com/OpenPrinting/cups/commit/0ff8897367c7341f2500770c3977038cdd7c0214
[2] https://security-tracker.debian.org/tracker/CVE-2026-34979

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-extended/cups/cups.inc           |  1 +
 .../cups/cups/CVE-2026-34979.patch            | 61 +++++++++++++++++++
 2 files changed, 62 insertions(+)
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34979.patch

diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index 7a8b845953c..a0ac1a26129 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -28,6 +28,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
            file://CVE-2026-34980.patch \
            file://CVE-2026-34980-regression_p1.patch \
            file://CVE-2026-34980-regression_p2.patch \
+           file://CVE-2026-34979.patch \
            "
 
 GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34979.patch b/meta/recipes-extended/cups/cups/CVE-2026-34979.patch
new file mode 100644
index 00000000000..38ac7b6e918
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34979.patch
@@ -0,0 +1,61 @@
+From 471b4dc802455c7c59f9fd594fec8b6f3acb0db5 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 31 Mar 2026 14:50:06 -0400
+Subject: [PATCH] Expand allocation of options string.
+
+CVE: CVE-2026-34979
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/0ff8897367c7341f2500770c3977038cdd7c0214]
+
+Backport Changes:
+- Rebase scheduler/job.c IPP length context to the CUPS 2.4.11 source
+  carried by this recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+  carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 0ff8897367c7341f2500770c3977038cdd7c0214)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/job.c |   16 ++++------------
+ 1 file changed, 4 insertions(+), 12 deletions(-)
+
+diff --git a/scheduler/job.c b/scheduler/job.c
+index 915ba94..880c25f 100644
+--- a/scheduler/job.c
++++ b/scheduler/job.c
+@@ -4195,18 +4195,6 @@ ipp_length(ipp_t *ipp)			/* I - IPP request */
+ 
+   for (attr = ipp->attrs; attr != NULL; attr = attr->next)
+   {
+-   /*
+-    * Skip attributes that won't be sent to filters...
+-    */
+-
+-    if (attr->value_tag == IPP_TAG_NOVALUE ||
+-	attr->value_tag == IPP_TAG_MIMETYPE ||
+-	attr->value_tag == IPP_TAG_NAMELANG ||
+-	attr->value_tag == IPP_TAG_TEXTLANG ||
+-	attr->value_tag == IPP_TAG_URI ||
+-	attr->value_tag == IPP_TAG_URISCHEME)
+-      continue;
+-
+    /*
+     * Add space for a leading space and commas between each value.
+     * For the first attribute, the leading space isn't used, so the
+@@ -4282,10 +4270,14 @@ ipp_length(ipp_t *ipp)			/* I - IPP request */
+ 
+       case IPP_TAG_TEXT :
+       case IPP_TAG_NAME :
++      case IPP_TAG_TEXTLANG :
++      case IPP_TAG_NAMELANG :
++      case IPP_TAG_MIMETYPE :
+       case IPP_TAG_KEYWORD :
+       case IPP_TAG_CHARSET :
+       case IPP_TAG_LANGUAGE :
+       case IPP_TAG_URI :
++      case IPP_TAG_URISCHEME :
+          /*
+ 	  * Strings can contain characters that need quoting.  We need
+ 	  * at least 2 * len + 2 characters to cover the quotes and
+-- 
+2.43.7
+


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 18/31] cups: fix CVE-2026-34990
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (16 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 17/31] cups: fix CVE-2026-34979 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 19/31] cups: fix CVE-2026-39314 Yoann Congal
                   ` (12 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

Pick the upstream patch [1] as mentioned in [2].

[1] https://github.com/OpenPrinting/cups/commit/e052dc44da9d12adfbebc51de4975fbadb2ce356
[2] https://security-tracker.debian.org/tracker/CVE-2026-34990

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-extended/cups/cups.inc           |   1 +
 .../cups/cups/CVE-2026-34990.patch            | 351 ++++++++++++++++++
 2 files changed, 352 insertions(+)
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34990.patch

diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index a0ac1a26129..1cef1e71fe4 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -29,6 +29,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
            file://CVE-2026-34980-regression_p1.patch \
            file://CVE-2026-34980-regression_p2.patch \
            file://CVE-2026-34979.patch \
+           file://CVE-2026-34990.patch \
            "
 
 GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34990.patch b/meta/recipes-extended/cups/cups/CVE-2026-34990.patch
new file mode 100644
index 00000000000..0a8c0930657
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34990.patch
@@ -0,0 +1,351 @@
+From 48648896ca7faa8f105eee7b7a8d86c42e0fa796 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 31 Mar 2026 15:55:50 -0400
+Subject: [PATCH] Don't allow local certificates over the loopback
+ interface, drop support for writing to plain files.
+
+CVE: CVE-2026-34990
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/e052dc44da9d12adfbebc51de4975fbadb2ce356]
+
+Backport Changes:
+- Preserve the existing CVE-2025-61915 PeerCred disable guard while changing
+  localhost checks to AF_LOCAL.
+- Keep the CUPS 2.4.11 empty device-uri validation path separate and add a
+  dedicated rejection for non-IPP/IPPS schemes instead of folding both checks
+  into one upstream condition.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+  carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit e052dc44da9d12adfbebc51de4975fbadb2ce356)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ cups/auth.c                    |   30 ++++++--------------------
+ scheduler/auth.c               |    9 ++++----
+ scheduler/client.c             |    4 +--
+ scheduler/ipp.c                |    8 ++++++-
+ scheduler/job.c                |   46 ++++++++++++++++++++++-------------------
+ test/4.2-cups-printer-ops.test |    6 ++---
+ test/5.1-lpadmin.sh            |   14 ++++++------
+ 7 files changed, 56 insertions(+), 61 deletions(-)
+
+diff --git a/cups/auth.c b/cups/auth.c
+index 5cb4194..14661c7 100644
+--- a/cups/auth.c
++++ b/cups/auth.c
+@@ -1,7 +1,7 @@
+ /*
+  * Authentication functions for CUPS.
+  *
+- * Copyright © 2020-2024 by OpenPrinting.
++ * Copyright © 2020-2026 by OpenPrinting.
+  * Copyright © 2007-2019 by Apple Inc.
+  * Copyright © 1997-2007 by Easy Software Products.
+  *
+@@ -92,7 +92,6 @@ static void	cups_gss_printf(OM_uint32 major_status, OM_uint32 minor_status,
+ #    define	cups_gss_printf(major, minor, message)
+ #  endif /* DEBUG */
+ #endif /* HAVE_GSSAPI */
+-static int	cups_is_local_connection(http_t *http);
+ static int	cups_local_auth(http_t *http);
+ 
+ 
+@@ -948,14 +947,6 @@ cups_gss_printf(OM_uint32  major_status,/* I - Major status code */
+ #  endif /* DEBUG */
+ #endif /* HAVE_GSSAPI */
+ 
+-static int				/* O - 0 if not a local connection */
+-					/*     1  if local connection */
+-cups_is_local_connection(http_t *http)	/* I - HTTP connection to server */
+-{
+-  if (!httpAddrLocalhost(http->hostaddr) && _cups_strcasecmp(http->hostname, "localhost") != 0)
+-    return 0;
+-  return 1;
+-}
+ 
+ /*
+  * 'cups_local_auth()' - Get the local authorization certificate if
+@@ -967,13 +958,7 @@ static int				/* O - 0 if available */
+ 					/*    -1 error */
+ cups_local_auth(http_t *http)		/* I - HTTP connection to server */
+ {
+-#if defined(_WIN32) || defined(__EMX__)
+- /*
+-  * Currently _WIN32 and OS-2 do not support the CUPS server...
+-  */
+-
+-  return (1);
+-#else
++#if !_WIN32 && !__EMX__ && defined(AF_LOCAL)
+   int			pid;		/* Current process ID */
+   FILE			*fp;		/* Certificate file */
+   char			trc[16],	/* Try Root Certificate parameter */
+@@ -998,7 +983,7 @@ cups_local_auth(http_t *http)		/* I - HTTP connection to server */
+   * See if we are accessing localhost...
+   */
+ 
+-  if (!cups_is_local_connection(http))
++  if (httpAddrFamily(httpGetAddress(http)) != AF_LOCAL)
+   {
+     DEBUG_puts("8cups_local_auth: Not a local connection!");
+     return (1);
+@@ -1072,15 +1057,14 @@ cups_local_auth(http_t *http)		/* I - HTTP connection to server */
+   }
+ #  endif /* HAVE_AUTHORIZATION_H */
+ 
+-#  if defined(SO_PEERCRED) && defined(AF_LOCAL)
++#  ifdef SO_PEERCRED
+  /*
+   * See if we can authenticate using the peer credentials provided over a
+   * domain socket; if so, specify "PeerCred username" as the authentication
+   * information...
+   */
+ 
+-  if (http->hostaddr->addr.sa_family == AF_LOCAL &&
+-      !getenv("GATEWAY_INTERFACE") &&	/* Not via CGI programs... */
++  if (!getenv("GATEWAY_INTERFACE") &&	/* Not via CGI programs... */
+       cups_auth_find(www_auth, "PeerCred"))
+   {
+    /*
+@@ -1104,7 +1088,7 @@ cups_local_auth(http_t *http)		/* I - HTTP connection to server */
+       return (0);
+     }
+   }
+-#  endif /* SO_PEERCRED && AF_LOCAL */
++#  endif /* SO_PEERCRED */
+ 
+   if ((schemedata = cups_auth_find(www_auth, "Local")) == NULL)
+     return (1);
+@@ -1164,7 +1148,7 @@ cups_local_auth(http_t *http)		/* I - HTTP connection to server */
+       return (0);
+     }
+   }
++#endif /* !_WIN32 && !__EMX__ && AF_LOCAL */
+ 
+   return (1);
+-#endif /* _WIN32 || __EMX__ */
+ }
+diff --git a/scheduler/auth.c b/scheduler/auth.c
+index 1dd520d..56855fc 100644
+--- a/scheduler/auth.c
++++ b/scheduler/auth.c
+@@ -318,7 +318,7 @@ cupsdAuthorize(cupsd_client_t *con)	/* I - Client connection */
+   }
+ #ifdef HAVE_AUTHORIZATION_H
+   else if (!strncmp(authorization, "AuthRef ", 8) &&
+-           httpAddrLocalhost(httpGetAddress(con->http)))
++           httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL)
+   {
+     OSStatus		status;		/* Status */
+     char		authdata[HTTP_MAX_VALUE];
+@@ -399,7 +399,8 @@ cupsdAuthorize(cupsd_client_t *con)	/* I - Client connection */
+ #endif /* HAVE_AUTHORIZATION_H */
+ #if defined(SO_PEERCRED) && defined(AF_LOCAL)
+-  else if (PeerCred != CUPSD_PEERCRED_OFF && !strncmp(authorization, "PeerCred ", 9) &&
+-           con->http->hostaddr->addr.sa_family == AF_LOCAL && con->best)
++  else if (PeerCred != CUPSD_PEERCRED_OFF &&
++           !strncmp(authorization, "PeerCred ", 9) &&
++           httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL && con->best)
+   {
+    /*
+     * Use peer credentials from domain socket connection...
+@@ -483,7 +483,7 @@ cupsdAuthorize(cupsd_client_t *con)	/* I - Client connection */
+   }
+ #endif /* SO_PEERCRED && AF_LOCAL */
+   else if (!strncmp(authorization, "Local", 5) &&
+-	   httpAddrLocalhost(httpGetAddress(con->http)))
++	   httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL)
+   {
+    /*
+     * Get Local certificate authentication data...
+diff --git a/scheduler/client.c b/scheduler/client.c
+index 779404c..dea9da0 100644
+--- a/scheduler/client.c
++++ b/scheduler/client.c
+@@ -2173,7 +2173,7 @@ cupsdSendHeader(
+       strlcpy(auth_str, "Negotiate", sizeof(auth_str));
+     }
+ 
+-    if (con->best && !con->is_browser && !_cups_strcasecmp(httpGetHostname(con->http, NULL, 0), "localhost"))
++    if (con->best && !con->is_browser && httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL)
+     {
+      /*
+       * Add a "trc" (try root certification) parameter for local
+@@ -2193,7 +2193,7 @@ cupsdSendHeader(
+       auth_size = sizeof(auth_str) - (size_t)(auth_key - auth_str);
+ 
+ #if defined(SO_PEERCRED) && defined(AF_LOCAL)
+-      if (PeerCred != CUPSD_PEERCRED_OFF && httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL)
++      if (PeerCred != CUPSD_PEERCRED_OFF)
+       {
+         strlcpy(auth_key, ", PeerCred", auth_size);
+         auth_key += 10;
+diff --git a/scheduler/ipp.c b/scheduler/ipp.c
+index b0d1f5b..11dcd39 100644
+--- a/scheduler/ipp.c
++++ b/scheduler/ipp.c
+@@ -5561,7 +5561,7 @@ create_local_printer(
+   * Require local access to create a local printer...
+   */
+ 
+-  if (!httpAddrLocalhost(httpGetAddress(con->http)))
++  if (httpAddrFamily(httpGetAddress(con->http)) != AF_LOCAL)
+   {
+     send_ipp_status(con, IPP_STATUS_ERROR_FORBIDDEN, _("Only local users can create a local printer."));
+     return;
+@@ -5634,6 +5634,12 @@ create_local_printer(
+ 
+     return;
+   }
++  else if (strncmp(ptr, "ipp://", 6) && strncmp(ptr, "ipps://", 7))
++  {
++    send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad device-uri \"%s\"."), ptr);
++
++    return;
++  }
+ 
+   printer_geo_location = ippFindAttribute(con->request, "printer-geo-location", IPP_TAG_URI);
+   printer_info         = ippFindAttribute(con->request, "printer-info", IPP_TAG_TEXT);
+diff --git a/scheduler/job.c b/scheduler/job.c
+index 880c25f..6c033de 100644
+--- a/scheduler/job.c
++++ b/scheduler/job.c
+@@ -1164,35 +1164,39 @@ cupsdContinueJob(cupsd_job_t *job)	/* I - Job */
+ 	}
+ 	else
+ 	{
++	  char	scheme[32],		/* URI scheme */
++		userpass[32],		/* URI username:password */
++		host[256],		/* URI hostname */
++		resource[1024];		/* URI resource path (filename) */
++	  int	port;			/* URI port number */
++
++          httpSeparateURI(HTTP_URI_CODING_ALL, job->printer->device_uri, scheme, sizeof(scheme), userpass, sizeof(userpass), host, sizeof(host), &port, resource, sizeof(resource));
++
+ 	  job->print_pipes[0] = -1;
+-	  if (!strcmp(job->printer->device_uri, "file:/dev/null") ||
+-	      !strcmp(job->printer->device_uri, "file:///dev/null"))
+-	    job->print_pipes[1] = -1;
+-	  else
++	  job->print_pipes[1] = -1;
++
++	  if (strcmp(resource, "/dev/null"))
+ 	  {
+-	    if (!strncmp(job->printer->device_uri, "file:/dev/", 10))
+-	      job->print_pipes[1] = open(job->printer->device_uri + 5,
+-	                        	 O_WRONLY | O_EXCL);
+-	    else if (!strncmp(job->printer->device_uri, "file:///dev/", 12))
+-	      job->print_pipes[1] = open(job->printer->device_uri + 7,
+-	                        	 O_WRONLY | O_EXCL);
+-	    else if (!strncmp(job->printer->device_uri, "file:///", 8))
+-	      job->print_pipes[1] = open(job->printer->device_uri + 7,
+-	                        	 O_WRONLY | O_CREAT | O_TRUNC, 0600);
+-	    else
+-	      job->print_pipes[1] = open(job->printer->device_uri + 5,
+-	                        	 O_WRONLY | O_CREAT | O_TRUNC, 0600);
++	    if (!FileDevice)
++	    {
++	      abort_message = "Stopping job because file: output is disabled.";
+ 
+-	    if (job->print_pipes[1] < 0)
++              goto abort_job;
++	    }
++	    else if ((job->print_pipes[1] = open(resource, O_WRONLY | O_EXCL)) < 0)
+ 	    {
+-	      abort_message = "Stopping job because the scheduler could not "
+-	                      "open the output file.";
++	      abort_message = "Stopping job because the scheduler could not open the output file.";
+ 
+               goto abort_job;
+ 	    }
++	    else
++	    {
++	     /*
++	      * Close this file on execute...
++	      */
+ 
+-	    fcntl(job->print_pipes[1], F_SETFD,
+-        	  fcntl(job->print_pipes[1], F_GETFD) | FD_CLOEXEC);
++	      fcntl(job->print_pipes[1], F_SETFD, fcntl(job->print_pipes[1], F_GETFD) | FD_CLOEXEC);
++	    }
+           }
+ 	}
+       }
+diff --git a/test/4.2-cups-printer-ops.test b/test/4.2-cups-printer-ops.test
+index 1a011e0..945a9bb 100644
+--- a/test/4.2-cups-printer-ops.test
++++ b/test/4.2-cups-printer-ops.test
+@@ -1,7 +1,7 @@
+ #
+ # Verify that the CUPS printer operations work.
+ #
+-# Copyright © 2020-2024 by OpenPrinting.
++# Copyright © 2020-2026 by OpenPrinting.
+ # Copyright © 2007-2019 by Apple Inc.
+ # Copyright © 2001-2006 by Easy Software Products. All rights reserved.
+ #
+@@ -180,7 +180,7 @@
+ 	ATTR uri printer-uri $method://$hostname:$port/printers/Test2
+ 
+ 	GROUP printer
+-	ATTR uri device-uri file:/tmp/Test2
++	ATTR uri device-uri file:///dev/null
+ 	ATTR enum printer-state 3
+ 	ATTR boolean printer-is-accepting-jobs true
+ 
+@@ -206,7 +206,7 @@
+ 	ATTR uri printer-uri $method://$hostname:$port/printers/Test1
+ 
+ 	GROUP printer
+-	ATTR uri device-uri file:/tmp/Test1
++	ATTR uri device-uri file:///dev/null
+ 	ATTR enum printer-state 3
+ 	ATTR boolean printer-is-accepting-jobs true
+ 	ATTR text printer-info "Test Printer 1"
+diff --git a/test/5.1-lpadmin.sh b/test/5.1-lpadmin.sh
+index aa39800..36f2822 100644
+--- a/test/5.1-lpadmin.sh
++++ b/test/5.1-lpadmin.sh
+@@ -2,7 +2,7 @@
+ #
+ # Test the lpadmin command.
+ #
+-# Copyright © 2020-2024 by OpenPrinting.
++# Copyright © 2020-2026 by OpenPrinting.
+ # Copyright © 2007-2018 by Apple Inc.
+ # Copyright © 1997-2005 by Easy Software Products, all rights reserved.
+ #
+@@ -12,8 +12,8 @@
+ 
+ echo "Add Printer Test"
+ echo ""
+-echo "    lpadmin -p Test3 -v file:/dev/null -E -m drv:///sample.drv/deskjet.ppd"
+-$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:/dev/null -E -m drv:///sample.drv/deskjet.ppd 2>&1
++echo "    lpadmin -p Test3 -v file:///dev/null -E -m drv:///sample.drv/deskjet.ppd"
++$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:///dev/null -E -m drv:///sample.drv/deskjet.ppd 2>&1
+ if test $? != 0; then
+ 	echo "    FAILED"
+ 	exit 1
+@@ -29,8 +29,8 @@ echo ""
+ 
+ echo "Modify Printer Test"
+ echo ""
+-echo "    lpadmin -p Test3 -v file:/tmp/Test3 -o PageSize=A4"
+-$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:/tmp/Test3 -o PageSize=A4 2>&1
++echo "    lpadmin -p Test3 -v file:///dev/null -o PageSize=A4"
++$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:///dev/null -o PageSize=A4 2>&1
+ if test $? != 0; then
+ 	echo "    FAILED"
+ 	exit 1
+@@ -65,8 +65,8 @@ echo ""
+ 
+ echo "Add a printer for cupSNMP/IPPSupplies test"
+ echo ""
+-echo "    lpadmin -p Test4 -E -v file:/dev/null -m drv:///sample.drv/zebra.ppd"
+-$runcups $VALGRIND ../systemv/lpadmin -p Test4 -E -v file:/dev/null -m drv:///sample.drv/zebra.ppd 2>&1
++echo "    lpadmin -p Test4 -E -v file:///dev/null -m drv:///sample.drv/zebra.ppd"
++$runcups $VALGRIND ../systemv/lpadmin -p Test4 -E -v file:///dev/null -m drv:///sample.drv/zebra.ppd 2>&1
+ if test $? != 0; then
+ 	echo "    FAILED"
+ 	exit 1
+-- 
+2.43.7


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 19/31] cups: fix CVE-2026-39314
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (17 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 18/31] cups: fix CVE-2026-34990 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 20/31] cups: fix CVE-2026-39316 Yoann Congal
                   ` (11 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

Pick the upstream patch [1] as mentioned in [2].

[1] https://github.com/OpenPrinting/cups/commit/928a86b1b794f738f0a3dc87561b2e054bff7ce4
[2] https://security-tracker.debian.org/tracker/CVE-2026-39314

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-extended/cups/cups.inc           |  1 +
 .../cups/cups/CVE-2026-39314.patch            | 45 +++++++++++++++++++
 2 files changed, 46 insertions(+)
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39314.patch

diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index 1cef1e71fe4..575dbf9c577 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -30,6 +30,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
            file://CVE-2026-34980-regression_p2.patch \
            file://CVE-2026-34979.patch \
            file://CVE-2026-34990.patch \
+           file://CVE-2026-39314.patch \
            "
 
 GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-39314.patch b/meta/recipes-extended/cups/cups/CVE-2026-39314.patch
new file mode 100644
index 00000000000..f8d1a69f56e
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-39314.patch
@@ -0,0 +1,45 @@
+From 65c463ada188915d6700d92ce48a9a14949ca413 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Sun, 5 Apr 2026 10:45:25 -0400
+Subject: [PATCH] Range check job-password-supported.
+
+CVE: CVE-2026-39314
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/928a86b1b794f738f0a3dc87561b2e054bff7ce4]
+
+Backport Changes:
+- Rebase cups/ppd-cache.c context to the CUPS 2.4.11 source carried by
+  this recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+  carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 928a86b1b794f738f0a3dc87561b2e054bff7ce4)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ cups/ppd-cache.c |    4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/cups/ppd-cache.c b/cups/ppd-cache.c
+index e750fcc..08e0db8 100644
+--- a/cups/ppd-cache.c
++++ b/cups/ppd-cache.c
+@@ -1,7 +1,7 @@
+ /*
+  * PPD cache implementation for CUPS.
+  *
+- * Copyright © 2022-2024 by OpenPrinting.
++ * Copyright © 2022-2026 by OpenPrinting.
+  * Copyright © 2010-2021 by Apple Inc.
+  *
+  * Licensed under Apache License v2.0.  See the file "LICENSE" for more
+@@ -3432,7 +3432,7 @@ _ppdCreateFromIPP2(
+   * Password/PIN printing...
+   */
+ 
+-  if ((attr = ippFindAttribute(supported, "job-password-supported", IPP_TAG_INTEGER)) != NULL)
++  if ((attr = ippFindAttribute(supported, "job-password-supported", IPP_TAG_INTEGER)) != NULL && ippGetInteger(attr, 0) > 0)
+   {
+     char	pattern[33];		/* Password pattern */
+     int		maxlen = ippGetInteger(attr, 0);
+-- 
+2.43.7
+


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 20/31] cups: fix CVE-2026-39316
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (18 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 19/31] cups: fix CVE-2026-39314 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 21/31] libxpm: fix CVE-2026-4367 Yoann Congal
                   ` (10 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

Pick the upstream patch [1] as mentioned in [2].

[1] https://github.com/OpenPrinting/cups/commit/0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f
[2] https://security-tracker.debian.org/tracker/CVE-2026-39316

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-extended/cups/cups.inc           |  1 +
 .../cups/cups/CVE-2026-39316.patch            | 40 +++++++++++++++++++
 2 files changed, 41 insertions(+)
 create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39316.patch

diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index 575dbf9c577..4c158aaee1b 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -31,6 +31,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
            file://CVE-2026-34979.patch \
            file://CVE-2026-34990.patch \
            file://CVE-2026-39314.patch \
+           file://CVE-2026-39316.patch \
            "
 
 GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-39316.patch b/meta/recipes-extended/cups/cups/CVE-2026-39316.patch
new file mode 100644
index 00000000000..d3c9edf9745
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-39316.patch
@@ -0,0 +1,40 @@
+From 7c4d7951d189e931563f21086196d5a55fb2fa15 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Sun, 5 Apr 2026 11:33:23 -0400
+Subject: [PATCH] Expire per-printer subscriptions before deleting.
+
+CVE: CVE-2026-39316
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f]
+
+Backport Changes:
+- Rebase scheduler/printers.c delete-printer context to the CUPS 2.4.11
+  source carried by this recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+  carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/printers.c |    6 ++++++
+ 1 file changed, 6 insertions(+)
+
+diff --git a/scheduler/printers.c b/scheduler/printers.c
+index bf493a3..ca983f9 100644
+--- a/scheduler/printers.c
++++ b/scheduler/printers.c
+@@ -641,6 +641,12 @@ cupsdDeletePrinter(
+                      update ? "Job stopped due to printer being deleted." :
+ 		              "Job stopped.");
+ 
++ /*
++  * Expire subscriptions on the printer...
++  */
++
++  cupsdExpireSubscriptions(p, /*job*/NULL);
++
+  /*
+   * Remove the printer from the list...
+   */
+-- 
+2.43.7
+


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 21/31] libxpm: fix CVE-2026-4367
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (19 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 20/31] cups: fix CVE-2026-39316 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 22/31] gnutls: set status for CVE-2026-3832 Yoann Congal
                   ` (9 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Enoch Ng <enoch.ng@windriver.com>

Backport the upstream fix for CVE-2026-4367, in which the
`xpmNextWord()` function could attempt to read beyond the file's
end due to improper validation of file boundaries.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4367

Signed-off-by: Enoch Ng <enoch.ng@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 ...67-Out-of-bounds-read-in-xpmNextWord.patch | 140 ++++++++++++++++++
 .../xorg-lib/libxpm_3.5.17.bb                 |   1 +
 2 files changed, 141 insertions(+)
 create mode 100644 meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch

diff --git a/meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch b/meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch
new file mode 100644
index 00000000000..e9989a5012c
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch
@@ -0,0 +1,140 @@
+From 5448e1bd7252780b16db869c2253d24e0fe0ae18 Mon Sep 17 00:00:00 2001
+From: Olivier Fourdan <ofourdan@redhat.com>
+Date: Tue, 17 Feb 2026 11:59:56 +0100
+Subject: [PATCH libXpm] Fix CVE-2026-4367: Out-of-bounds read in xpmNextWord()
+
+xpmNextWord() checks for the terminator character to detect the end of
+the file, but a very small malformed XPM file may cause the function to
+read past the end of the buffer, causing out-of-bound reads:
+
+  == Invalid read of size 1
+  ==    at 0x48AD3A4: xpmParseColors (parse.c:239)
+  ==    by 0x48AF9D8: xpmParseData (parse.c:783)
+  ==    by 0x48B1C18: XpmCreateXpmImageFromBuffer (CrIFrBuf.c:101)
+  ==    by 0x4005A6: main ()
+  ==  Address 0x4c413bf is 0 bytes after a block of size 15 alloc'd
+  ==    at 0x4841B26: malloc (vg_replace_malloc.c:447)
+  ==    by 0x48B2809: XpmReadFileToBuffer (RdFToBuf.c:96)
+  ==    by 0x400554: main ()
+  ==
+  == Invalid read of size 1
+  ==    at 0x48AC8D5: xpmNextWord.constprop.0 (data.c:262)
+  ==    by 0x48AD492: xpmParseColors (parse.c:266)
+  ==    by 0x48AF9D8: xpmParseData (parse.c:783)
+  ==    by 0x48B1C18: XpmCreateXpmImageFromBuffer (CrIFrBuf.c:101)
+  ==    by 0x4005A6: main ()
+  ==  Address 0x4c413c0 is 1 bytes after a block of size 15 alloc'd
+  ==    at 0x4841B26: malloc (vg_replace_malloc.c:447)
+  ==    by 0x48B2809: XpmReadFileToBuffer (RdFToBuf.c:96)
+  ==    by 0x400554: main ()
+  ==
+  == Invalid read of size 1
+  ==    at 0x48AC965: xpmNextWord.constprop.0 (data.c:265)
+  ==    by 0x48AD492: xpmParseColors (parse.c:266)
+  ==    by 0x48AF9D8: xpmParseData (parse.c:783)
+  ==    by 0x48B1C18: XpmCreateXpmImageFromBuffer (CrIFrBuf.c:101)
+  ==    by 0x4005A6: main ()
+  ==  Address 0x4c413c0 is 1 bytes after a block of size 15 alloc'd
+  ==    at 0x4841B26: malloc (vg_replace_malloc.c:447)
+  ==    by 0x48B2809: XpmReadFileToBuffer (RdFToBuf.c:96)
+  ==    by 0x400554: main ()
+
+The problem actually comes from xpmNextString() and xpmParseColors():
+
+1) xpmNextString() checks for the NULL terminator when looking for the
+   end of the string (Eos) but not when looking for the beginning of the
+   next string (Bos).
+
+2) xpmParseColors() does not check the return value from xpmNextString()
+   and continues even when xpmNextString() raised an invalid XPM file.
+
+To avoid the issue, fix xpmNextString() to check for the NULL string
+terminator when looking for the beginning of the next string and fix
+xpmParseColors() to stop when xpmNextString() reported an invalid XPM
+error.
+
+CVE-2026-4367
+
+This vulnerability was discovered by:
+Naoki Wakamatsu
+
+v2: Fix the XPM 1 code path the same.
+
+Signed-off-by: Olivier Fourdan <ofourdan@redhat.com>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/31>
+
+CVE: CVE-2026-4367
+Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/5448e1bd7252780b16db869c2253d24e0fe0ae18]
+Signed-off-by: Enoch Ng <enoch.ng@windriver.com>
+
+---
+
+ src/data.c  |  3 +++
+ src/parse.c | 19 ++++++++++++++-----
+ 2 files changed, 17 insertions(+), 5 deletions(-)
+
+diff --git a/src/data.c b/src/data.c
+index 6e87455..a2b4acc 100644
+--- a/src/data.c
++++ b/src/data.c
+@@ -210,6 +210,9 @@ xpmNextString(xpmData *data)
+ 	    while ((c = *data->cptr++) && c != data->Bos && c != '\0')
+ 		if (data->Bcmt && c == data->Bcmt[0])
+ 		    ParseComment(data);
++
++	    if (c == '\0')
++		return XpmFileInvalid;
+ 	} else if (data->Bcmt) {	/* XPM2 natural */
+ 	    while (((c = *data->cptr++) == data->Bcmt[0]) && c != '\0')
+ 		ParseComment(data);
+diff --git a/src/parse.c b/src/parse.c
+index cd923f9..268954d 100644
+--- a/src/parse.c
++++ b/src/parse.c
+@@ -216,7 +216,9 @@ xpmParseColors(
+ 
+     if (!data->format) {		/* XPM 2 or 3 */
+ 	for (a = 0, color = colorTable; a < ncolors; a++, color++) {
+-	    xpmNextString(data);	/* skip the line */
++	    ErrorStatus = xpmNextString(data);         /* skip the line */
++	    if (ErrorStatus != XpmSuccess)
++		goto error;
+ 
+ 	    /*
+ 	     * read pixel value
+@@ -314,7 +316,9 @@ xpmParseColors(
+ 	/* get to the beginning of the first string */
+ 	data->Bos = '"';
+ 	data->Eos = '\0';
+-	xpmNextString(data);
++	ErrorStatus = xpmNextString(data);
++	if (ErrorStatus != XpmSuccess)
++	    goto error;
+ 	data->Eos = '"';
+ 	for (a = 0, color = colorTable; a < ncolors; a++, color++) {
+ 
+@@ -354,7 +358,9 @@ xpmParseColors(
+ 	    /*
+ 	     * read color values
+ 	     */
+-	    xpmNextString(data);	/* get to the next string */
++	    ErrorStatus = xpmNextString(data);	/* get to the next string */
++	    if (ErrorStatus != XpmSuccess)
++		goto error;
+ 	    *curbuf = '\0';		/* init curbuf */
+ 	    while ((l = xpmNextWord(data, buf, BUFSIZ))) {
+ 		if (*curbuf != '\0') {
+@@ -378,8 +384,11 @@ xpmParseColors(
+ 	    memcpy(s, curbuf, len);
+ 	    color->c_color = s;
+ 	    *curbuf = '\0';		/* reset curbuf */
+-	    if (a < ncolors - 1)	/* can we trust ncolors -> leave data's bounds */
+-		xpmNextString(data);	/* get to the next string */
++	    if (a < ncolors - 1) {	/* can we trust ncolors -> leave data's bounds */
++		ErrorStatus = xpmNextString(data);	/* get to the next string */
++		if (ErrorStatus != XpmSuccess)
++		    goto error;
++	    }
+ 	}
+     }
+     *colorTablePtr = colorTable;
diff --git a/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb b/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb
index 8e15ecc0d48..9d1dd477429 100644
--- a/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb
+++ b/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb
@@ -22,6 +22,7 @@ PACKAGES =+ "sxpm cxpm"
 FILES:cxpm = "${bindir}/cxpm"
 FILES:sxpm = "${bindir}/sxpm"
 
+SRC_URI += " file://0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch"
 SRC_URI[sha256sum] = "64b31f81019e7d388c822b0b28af8d51c4622b83f1f0cb6fa3fc95e271226e43"
 
 BBCLASSEXTEND = "native"


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 22/31] gnutls: set status for CVE-2026-3832
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (20 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 21/31] libxpm: fix CVE-2026-4367 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 23/31] gnutls: fix CVE-2026-42009 Yoann Congal
                   ` (8 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Sudhir Dumbhare <sudumbha@cisco.com>

Analysis:
  - CVE-2026-3832 affects GnuTLS OCSP multi-record response handling.
  - The vulnerable OCSP response handling code was introduced in GnuTLS 3.8.8.
  - This vulnerable code is not present in the current GnuTLS 3.8.4.
  - Hence ignoring the CVE for this version.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-3832
https://security-tracker.debian.org/tracker/CVE-2026-3832
https://gitlab.com/gnutls/gnutls/-/issues/1801

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-support/gnutls/gnutls_3.8.4.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb
index ccb6a2b4b2d..6d43c58df27 100644
--- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb
+++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb
@@ -124,3 +124,5 @@ pkg_postinst_ontarget:${PN}-fips () {
         ${bindir}/fipshmac ${libdir}/libhogweed.so.6.* > ${libdir}/.libhogweed.so.6.hmac
     fi
 }
+
+CVE_STATUS[CVE-2026-3832] = "fixed-version: vulnerable multi-record OCSP response handling was introduced in 3.8.8 and is not present in 3.8.4"


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 23/31] gnutls: fix CVE-2026-42009
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (21 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 22/31] gnutls: set status for CVE-2026-3832 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 24/31] libpng: Fix CVE-2026-34757 Yoann Congal
                   ` (7 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Sudhir Dumbhare <sudumbha@cisco.com>

This patch applies the upstream fix [1] and [2], as referenced in [3],
to address a DTLS packet reordering flaw where duplicate sequence numbers
could lead to unstable ordering or undefined behavior.

[1] https://gitlab.com/gnutls/gnutls/-/commit/f01e21441e29052a6f0963840794c41d3b3ee66d
[2] https://gitlab.com/gnutls/gnutls/-/commit/f341441fad91142897d83b44a175ffc8f925b76f
[3] https://security-tracker.debian.org/tracker/CVE-2026-42009

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-42009

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../gnutls/gnutls/CVE-2026-42009_p1.patch     | 66 +++++++++++++++++++
 .../gnutls/gnutls/CVE-2026-42009_p2.patch     | 47 +++++++++++++
 meta/recipes-support/gnutls/gnutls_3.8.4.bb   |  2 +
 3 files changed, 115 insertions(+)
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch

diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch
new file mode 100644
index 00000000000..03214bab0ea
--- /dev/null
+++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch
@@ -0,0 +1,66 @@
+From e1f366666c12f431151a04ada9cf9a30d602751b Mon Sep 17 00:00:00 2001
+From: Alexander Sosedkin <asosedkin@redhat.com>
+Date: Tue, 21 Apr 2026 16:52:48 +0200
+Subject: [PATCH] lib/buffers: ensure packets have differing sequence
+ numbers
+
+There should normally be no packets with same sequence number and
+differing handshake type, unless an adversary crafts them.
+Discarding them allows to get rid of packets
+with duplicate sequence ID in the buffer,
+relieving us from the question of how to sort them later.
+
+CVE: CVE-2026-42009
+Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/f01e21441e29052a6f0963840794c41d3b3ee66d]
+
+Backport Changes:
+- Adjusted the upstream hunk to match the GnuTLS 3.8.4 code layout.
+- The upstream commit uses the local recv_buf alias introduced later
+  in v3.8.13 by commit;
+  https://gitlab.com/gnutls/gnutls/-/commit/9deffca528c23bbb218f5ec3bd4bb1bf4cbd1fc0.
+- GnuTLS 3.8.4 does not have that local recv_buf alias in
+  merge_handshake_packet(), so the backport replaces recv_buf[i] with the
+  existing session->internals.handshake_recv_buffer[i] access pattern.
+
+Reported-by: Joshua Rogers of AISLE Research Team <joshua@joshua.hu>
+Fixes: #1848
+Fixes: CVE-2026-42009
+Fixes: GNUTLS-SA-2026-04-29-2
+CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
+Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
+(cherry picked from commit f01e21441e29052a6f0963840794c41d3b3ee66d)
+Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
+---
+ lib/buffers.c | 16 ++++++++++++++--
+ 1 file changed, 14 insertions(+), 2 deletions(-)
+
+diff --git a/lib/buffers.c b/lib/buffers.c
+index 672380b054..e7f08b5625 100644
+--- a/lib/buffers.c
++++ b/lib/buffers.c
+@@ -968,8 +968,20 @@ static int merge_handshake_packet(gnutls_session_t session,
+ 	int ret;
+ 
+ 	for (i = 0; i < session->internals.handshake_recv_buffer_size; i++) {
+-		if (session->internals.handshake_recv_buffer[i].htype ==
+-		    hsk->htype) {
++		if (session->internals.handshake_recv_buffer[i].sequence == hsk->sequence) {
++			if (session->internals.handshake_recv_buffer[i].htype != hsk->htype) {
++				_gnutls_audit_log(
++					session,
++					"Discarded unexpected handshake packet "
++					"with duplicate sequence %d, but "
++					"mismatched type %s (previously %s)\n",
++					hsk->sequence,
++					_gnutls_handshake2str(hsk->htype),
++					_gnutls_handshake2str(
++						session->internals.handshake_recv_buffer[i].htype));
++				_gnutls_handshake_buffer_clear(hsk);
++				return 0;
++			}
+ 			exists = 1;
+ 			pos = i;
+ 			break;
+-- 
+2.35.6
+
diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch
new file mode 100644
index 00000000000..b26491840b5
--- /dev/null
+++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch
@@ -0,0 +1,47 @@
+From 23fdcec4c6b5669296295ad3a9f87f6467eeb0f3 Mon Sep 17 00:00:00 2001
+From: Joshua Rogers <joshua@joshua.hu>
+Date: Tue, 21 Apr 2026 18:11:39 +0200
+Subject: [PATCH] buffers: fix handshake_compare when sequence numbers
+ match
+
+The comparator function used for ordering DTLS packets
+by sequence numbers did not follow qsort comparator contracts
+in case of packets with duplicate sequence numbers,
+which could lead to unstable ordering or undefined behaviour.
+Returning 0 in such cases makes the sorting stable.
+
+CVE: CVE-2026-42009
+Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/f341441fad91142897d83b44a175ffc8f925b76f]
+
+Reported-by: Joshua Rogers of AISLE Research Team <joshua@joshua.hu>
+Fixes: #1848
+Fixes: CVE-2026-42009
+Fixes: GNUTLS-SA-2026-04-29-2
+CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
+Signed-off-by: Joshua Rogers <joshua@joshua.hu>
+(cherry picked from commit f341441fad91142897d83b44a175ffc8f925b76f)
+Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
+---
+ lib/buffers.c | 6 +-----
+ 1 file changed, 1 insertion(+), 5 deletions(-)
+
+diff --git a/lib/buffers.c b/lib/buffers.c
+index e7f08b5625..1ac27e4e96 100644
+--- a/lib/buffers.c
++++ b/lib/buffers.c
+@@ -844,11 +844,7 @@ static int handshake_compare(const void *_e1, const void *_e2)
+ {
+ 	const handshake_buffer_st *e1 = _e1;
+ 	const handshake_buffer_st *e2 = _e2;
+-
+-	if (e1->sequence <= e2->sequence)
+-		return 1;
+-	else
+-		return -1;
++	return (e1->sequence < e2->sequence) - (e1->sequence > e2->sequence);
+ }
+ 
+ #define SSL2_HEADERS 1
+-- 
+2.35.6
+
diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb
index 6d43c58df27..d27d2cfa748 100644
--- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb
+++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb
@@ -43,6 +43,8 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar
            file://CVE-2025-14831-7.patch \
            file://CVE-2025-14831-8.patch \
            file://CVE-2025-14831-9.patch \
+           file://CVE-2026-42009_p1.patch \
+           file://CVE-2026-42009_p2.patch \
            "
 
 SRC_URI[sha256sum] = "2bea4e154794f3f00180fa2a5c51fe8b005ac7a31cd58bd44cdfa7f36ebc3a9b"


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 24/31] libpng: Fix CVE-2026-34757
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (22 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 23/31] gnutls: fix CVE-2026-42009 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 25/31] glib-2.0: fix CVE-2026-58010 Yoann Congal
                   ` (6 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Sudhir Dumbhare <sudumbha@cisco.com>

These patches apply the upstream fixes [1][2], which address
getter-to-setter aliasing issues in libpng chunk setters that could
cause stale-pointer reads, as described in [3].

[1] https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a
[2] https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc
[3] https://github.com/pnggroup/libpng/issues/836

Reference:
https://security-tracker.debian.org/tracker/CVE-2026-34757
https://nvd.nist.gov/vuln/detail/CVE-2026-34757

Test results on qemux86-64 using ptest-runner:
START: ptest-runner
2026-06-04T11:29
BEGIN: /usr/lib/libpng/ptest
PASS: tests/pnggetset
Testsuite summary
# TOTAL: 33
# PASS:  33
# SKIP:  0
# XFAIL: 0
# FAIL:  0
# XPASS: 0
# ERROR: 0
DURATION: 80
END: /usr/lib/libpng/ptest
2026-06-04T11:31
STOP: ptest-runner
TOTAL: 1 FAIL: 0

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../libpng/files/CVE-2026-34757_p1.patch      | 521 ++++++++++++++++++
 .../libpng/files/CVE-2026-34757_p2.patch      | 484 ++++++++++++++++
 .../libpng/libpng_1.6.42.bb                   |   4 +-
 3 files changed, 1008 insertions(+), 1 deletion(-)
 create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
 create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch

diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
new file mode 100644
index 00000000000..cd8150b1a45
--- /dev/null
+++ b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
@@ -0,0 +1,521 @@
+From 1fb509cdff1f9d83e2bf160259529a742de9285f Mon Sep 17 00:00:00 2001
+From: Cosmin Truta <ctruta@gmail.com>
+Date: Mon, 30 Mar 2026 17:35:30 +0300
+Subject: [PATCH] fix: Handle self-referencing pointers in getter-to-setter
+ aliasing
+
+Apply a robustness fix for a caller-side API usage pattern involving
+the getters and the setters for PLTE, tRNS, and hIST.
+
+Passing a pointer returned by the PLTE, tRNS, or hIST getters back
+into the corresponding setters used to cause the setters to read from
+a stale pointer. The fix consists in snapshotting the caller's data
+into a stack-local buffer before freeing the old internal storage.
+
+Fixes pnggroup/libpng#836
+
+CVE: CVE-2026-34757
+Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a]
+
+Reported-by: Iv4n <Iv4n550@noreply.github.com>
+(cherry picked from commit 398cbe3df03f4e11bb031e07f416dfdde3684e8a)
+Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
+---
+ CMakeLists.txt               |  12 ++
+ Makefile.am                  |   9 +-
+ contrib/libtests/pnggetset.c | 328 +++++++++++++++++++++++++++++++++++
+ pngset.c                     |  29 +++-
+ tests/pnggetset              |   5 +
+ 5 files changed, 380 insertions(+), 3 deletions(-)
+ create mode 100644 contrib/libtests/pnggetset.c
+ create mode 100755 tests/pnggetset
+
+diff --git a/CMakeLists.txt b/CMakeLists.txt
+index 93a2c3434..8888d15cb 100644
+--- a/CMakeLists.txt
++++ b/CMakeLists.txt
+@@ -591,6 +591,9 @@ set(pngvalid_sources
+ set(pngstest_sources
+     contrib/libtests/pngstest.c
+ )
++set(pnggetset_sources
++    contrib/libtests/pnggetset.c
++)
+ set(pngunknown_sources
+     contrib/libtests/pngunknown.c
+ )
+@@ -758,6 +761,15 @@ if(PNG_TESTS AND PNG_SHARED)
+                COMMAND pngtest
+                FILES "${PNGTEST_PNG}")
+ 
++  # pnggetset test:
++  # Getter-to-setter roundtrips for various chunk types.
++  add_executable(pnggetset ${pnggetset_sources})
++  target_link_libraries(pnggetset
++                        PRIVATE png_shared)
++
++  png_add_test(NAME pnggetset
++               COMMAND pnggetset)
++
+   add_executable(pngvalid ${pngvalid_sources})
+   target_link_libraries(pngvalid PRIVATE png_shared)
+ 
+diff --git a/Makefile.am b/Makefile.am
+index 1f06c703a..bdb40c61c 100644
+--- a/Makefile.am
++++ b/Makefile.am
+@@ -13,7 +13,7 @@ ACLOCAL_AMFLAGS = -I scripts/autoconf
+ 
+ # test programs - run on make check, make distcheck
+ if ENABLE_TESTS
+-check_PROGRAMS= pngtest pngunknown pngstest pngvalid pngimage pngcp
++check_PROGRAMS= pngtest pnggetset pngunknown pngstest pngvalid pngimage pngcp
+ if HAVE_CLOCK_GETTIME
+ check_PROGRAMS += timepng
+ endif
+@@ -42,6 +42,9 @@ if ENABLE_TESTS
+ pngtest_SOURCES = pngtest.c
+ pngtest_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la
+ 
++pnggetset_SOURCES = contrib/libtests/pnggetset.c
++pnggetset_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la
++
+ pngvalid_SOURCES = contrib/libtests/pngvalid.c
+ pngvalid_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la
+ 
+@@ -75,6 +78,7 @@ TESTS =\
+    tests/pngtest-all\
+    tests/pngvalid-gamma-16-to-8 tests/pngvalid-gamma-alpha-mode\
+    tests/pngvalid-gamma-background tests/pngvalid-gamma-expand16-alpha-mode\
++   tests/pnggetset\
+    tests/pngvalid-gamma-expand16-background\
+    tests/pngvalid-gamma-expand16-transform tests/pngvalid-gamma-sbit\
+    tests/pngvalid-gamma-threshold tests/pngvalid-gamma-transform\
+@@ -273,9 +277,10 @@ $(srcdir)/scripts/pnglibconf.h.prebuilt:
+ pngtest.o: pnglibconf.h
+ 
+ contrib/libtests/makepng.o: pnglibconf.h
++contrib/libtests/pnggetset.o: pnglibconf.h
++contrib/libtests/pngimage.o: pnglibconf.h
+ contrib/libtests/pngstest.o: pnglibconf.h
+ contrib/libtests/pngunknown.o: pnglibconf.h
+-contrib/libtests/pngimage.o: pnglibconf.h
+ contrib/libtests/pngvalid.o: pnglibconf.h
+ contrib/libtests/readpng.o: pnglibconf.h
+ contrib/libtests/tarith.o: pnglibconf.h
+diff --git a/contrib/libtests/pnggetset.c b/contrib/libtests/pnggetset.c
+new file mode 100644
+index 000000000..b42508094
+--- /dev/null
++++ b/contrib/libtests/pnggetset.c
+@@ -0,0 +1,328 @@
++/* pnggetset.c
++ *
++ * Copyright (c) 2026 Cosmin Truta
++ *
++ * This code is released under the libpng license.
++ * For conditions of distribution and use, see the disclaimer
++ * and license in png.h
++ *
++ * Test the get-then-set roundtrip pattern for PLTE, tRNS, and hIST.
++ *
++ * Passing the internal pointer returned by a getter back into the
++ * corresponding setter is a natural API usage pattern.  A previous
++ * version had a use-after-free on this path because the setter freed
++ * the internal buffer before copying from the caller-supplied pointer.
++ */
++
++#include <stdio.h>
++#include <stdlib.h>
++#include <string.h>
++
++#if defined(HAVE_CONFIG_H) && !defined(PNG_NO_CONFIG_H)
++#  include <config.h>
++#endif
++
++#ifdef PNG_FREESTANDING_TESTS
++#  include <png.h>
++#else
++#  include "../../png.h"
++#endif
++
++/* Test: get the PLTE, pass it straight back to set, verify roundtrip. */
++static int
++test_plte_roundtrip(void)
++{
++   png_structp png_ptr;
++   png_infop info_ptr;
++   png_color palette[4];
++   png_colorp got_palette = NULL;
++   int num_palette = 0;
++   int i;
++
++   png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++       NULL, NULL, NULL);
++   if (png_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++      return 1;
++   }
++
++   info_ptr = png_create_info_struct(png_ptr);
++   if (info_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++      png_destroy_write_struct(&png_ptr, NULL);
++      return 1;
++   }
++
++   if (setjmp(png_jmpbuf(png_ptr)))
++   {
++      fprintf(stderr, "pnggetset: libpng error in test_plte_roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* Set up a palette-color image header. */
++   png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE,
++       PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE);
++
++   /* Populate with recognizable values. */
++   for (i = 0; i < 4; i++)
++   {
++      palette[i].red   = (png_byte)(i * 10);
++      palette[i].green = (png_byte)(i * 20);
++      palette[i].blue  = (png_byte)(i * 30);
++   }
++   png_set_PLTE(png_ptr, info_ptr, palette, 4);
++
++   /* Get the internal pointer and feed it straight back. */
++   png_get_PLTE(png_ptr, info_ptr, &got_palette, &num_palette);
++   if (got_palette == NULL || num_palette != 4)
++   {
++      fprintf(stderr, "pnggetset: png_get_PLTE returned unexpected values\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* This is the critical call: the pointer aliases info_ptr->palette. */
++   png_set_PLTE(png_ptr, info_ptr, got_palette, num_palette);
++
++   /* Verify the data survived the roundtrip. */
++   got_palette = NULL;
++   num_palette = 0;
++   png_get_PLTE(png_ptr, info_ptr, &got_palette, &num_palette);
++   if (got_palette == NULL || num_palette != 4)
++   {
++      fprintf(stderr, "pnggetset: PLTE lost after roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++   for (i = 0; i < 4; i++)
++   {
++      if (got_palette[i].red   != (png_byte)(i * 10) ||
++          got_palette[i].green != (png_byte)(i * 20) ||
++          got_palette[i].blue  != (png_byte)(i * 30))
++      {
++         fprintf(stderr,
++             "pnggetset: PLTE entry %d corrupted after roundtrip\n", i);
++         png_destroy_write_struct(&png_ptr, &info_ptr);
++         return 1;
++      }
++   }
++
++   png_destroy_write_struct(&png_ptr, &info_ptr);
++   return 0;
++}
++
++#ifdef PNG_hIST_SUPPORTED
++/* Test: get the hIST, pass it straight back to set, verify roundtrip. */
++static int
++test_hist_roundtrip(void)
++{
++   png_structp png_ptr;
++   png_infop info_ptr;
++   png_color palette[4];
++   png_uint_16 hist[4];
++   png_uint_16p got_hist = NULL;
++   int i;
++
++   png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++       NULL, NULL, NULL);
++   if (png_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++      return 1;
++   }
++
++   info_ptr = png_create_info_struct(png_ptr);
++   if (info_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++      png_destroy_write_struct(&png_ptr, NULL);
++      return 1;
++   }
++
++   if (setjmp(png_jmpbuf(png_ptr)))
++   {
++      fprintf(stderr, "pnggetset: libpng error in test_hist_roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* Set up a palette-color image header. */
++   memset(palette, 0, sizeof palette);
++   png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE,
++       PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE);
++   png_set_PLTE(png_ptr, info_ptr, palette, 4);
++
++   /* Populate with recognizable values. */
++   for (i = 0; i < 4; i++)
++      hist[i] = (png_uint_16)(i * 100 + 42);
++
++   png_set_hIST(png_ptr, info_ptr, hist);
++
++   /* Get the internal pointer and feed it straight back. */
++   if (png_get_hIST(png_ptr, info_ptr, &got_hist) == 0 || got_hist == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_get_hIST returned unexpected values\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* This is the critical call: the pointer aliases info_ptr->hist. */
++   png_set_hIST(png_ptr, info_ptr, got_hist);
++
++   /* Verify the data survived the roundtrip. */
++   got_hist = NULL;
++   if (png_get_hIST(png_ptr, info_ptr, &got_hist) == 0 || got_hist == NULL)
++   {
++      fprintf(stderr, "pnggetset: hIST lost after roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++   for (i = 0; i < 4; i++)
++   {
++      if (got_hist[i] != (png_uint_16)(i * 100 + 42))
++      {
++         fprintf(stderr,
++             "pnggetset: hIST entry %d corrupted after roundtrip\n", i);
++         png_destroy_write_struct(&png_ptr, &info_ptr);
++         return 1;
++      }
++   }
++
++   png_destroy_write_struct(&png_ptr, &info_ptr);
++   return 0;
++}
++#endif /* PNG_hIST_SUPPORTED */
++
++#ifdef PNG_tRNS_SUPPORTED
++/* Test: get the tRNS, pass it straight back to set, verify roundtrip. */
++static int
++test_trns_roundtrip(void)
++{
++   png_structp png_ptr;
++   png_infop info_ptr;
++   png_color palette[4];
++   png_byte trans_alpha[4];
++   png_color_16 trans_color;
++   png_bytep got_alpha = NULL;
++   png_color_16p got_color = NULL;
++   int num_trans = 0;
++   int i;
++
++   png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++       NULL, NULL, NULL);
++   if (png_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++      return 1;
++   }
++
++   info_ptr = png_create_info_struct(png_ptr);
++   if (info_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++      png_destroy_write_struct(&png_ptr, NULL);
++      return 1;
++   }
++
++   if (setjmp(png_jmpbuf(png_ptr)))
++   {
++      fprintf(stderr, "pnggetset: libpng error in test_trns_roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* Set up a palette-color image. */
++   memset(palette, 0, sizeof palette);
++   png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE,
++       PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE);
++   png_set_PLTE(png_ptr, info_ptr, palette, 4);
++
++   /* Populate tRNS with recognizable values. */
++   for (i = 0; i < 4; i++)
++      trans_alpha[i] = (png_byte)(0xff - i * 0x11);
++   memset(&trans_color, 0, sizeof trans_color);
++
++   png_set_tRNS(png_ptr, info_ptr, trans_alpha, 4, &trans_color);
++
++   /* Get the internal pointer and feed it straight back. */
++   png_get_tRNS(png_ptr, info_ptr, &got_alpha, &num_trans, &got_color);
++   if (got_alpha == NULL || num_trans != 4)
++   {
++      fprintf(stderr, "pnggetset: png_get_tRNS returned unexpected values\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* This is the critical call: the pointer aliases info_ptr->trans_alpha. */
++   png_set_tRNS(png_ptr, info_ptr, got_alpha, num_trans, got_color);
++
++   /* Verify the data survived the roundtrip. */
++   got_alpha = NULL;
++   num_trans = 0;
++   png_get_tRNS(png_ptr, info_ptr, &got_alpha, &num_trans, &got_color);
++   if (got_alpha == NULL || num_trans != 4)
++   {
++      fprintf(stderr, "pnggetset: tRNS lost after roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++   for (i = 0; i < 4; i++)
++   {
++      if (got_alpha[i] != (png_byte)(0xff - i * 0x11))
++      {
++         fprintf(stderr,
++             "pnggetset: tRNS entry %d corrupted after roundtrip\n", i);
++         png_destroy_write_struct(&png_ptr, &info_ptr);
++         return 1;
++      }
++   }
++
++   png_destroy_write_struct(&png_ptr, &info_ptr);
++   return 0;
++}
++#endif /* PNG_tRNS_SUPPORTED */
++
++int
++main(void)
++{
++   int result = 0;
++
++   printf("Testing PLTE get-then-set roundtrip... ");
++   fflush(stdout);
++   if (test_plte_roundtrip() != 0)
++   {
++      printf("FAIL\n");
++      result = 1;
++   }
++   else
++      printf("PASS\n");
++
++#ifdef PNG_hIST_SUPPORTED
++   printf("Testing hIST get-then-set roundtrip... ");
++   fflush(stdout);
++   if (test_hist_roundtrip() != 0)
++   {
++      printf("FAIL\n");
++      result = 1;
++   }
++   else
++      printf("PASS\n");
++#endif
++
++#ifdef PNG_tRNS_SUPPORTED
++   printf("Testing tRNS get-then-set roundtrip... ");
++   fflush(stdout);
++   if (test_trns_roundtrip() != 0)
++   {
++      printf("FAIL\n");
++      result = 1;
++   }
++   else
++      printf("PASS\n");
++#endif
++
++   return result;
++}
+diff --git a/pngset.c b/pngset.c
+index c4a0958aa..9f5c44510 100644
+--- a/pngset.c
++++ b/pngset.c
+@@ -204,6 +204,7 @@ void PNGAPI
+ png_set_hIST(png_const_structrp png_ptr, png_inforp info_ptr,
+     png_const_uint_16p hist)
+ {
++   png_uint_16 safe_hist[PNG_MAX_PALETTE_LENGTH];
+    int i;
+ 
+    png_debug1(1, "in %s storage function", "hIST");
+@@ -220,6 +221,13 @@ png_set_hIST(png_const_structrp png_ptr, png_inforp info_ptr,
+       return;
+    }
+ 
++   /* Snapshot the caller's hist before freeing, in case it points to
++    * info_ptr->hist (getter-to-setter aliasing).
++    */
++   memcpy(safe_hist, hist, (unsigned int)info_ptr->num_palette *
++       (sizeof (png_uint_16)));
++   hist = safe_hist;
++
+    png_free_data(png_ptr, info_ptr, PNG_FREE_HIST, 0);
+ 
+    /* Changed from info->num_palette to PNG_MAX_PALETTE_LENGTH in
+@@ -561,7 +569,7 @@ void PNGAPI
+ png_set_PLTE(png_structrp png_ptr, png_inforp info_ptr,
+     png_const_colorp palette, int num_palette)
+ {
+-
++   png_color safe_palette[PNG_MAX_PALETTE_LENGTH];
+    png_uint_32 max_palette_length;
+ 
+    png_debug1(1, "in %s storage function", "PLTE");
+@@ -595,6 +603,15 @@ png_set_PLTE(png_structrp png_ptr, png_inforp info_ptr,
+       png_error(png_ptr, "Invalid palette");
+    }
+ 
++   /* Snapshot the caller's palette before freeing, in case it points to
++    * info_ptr->palette (getter-to-setter aliasing).
++    */
++   if (num_palette > 0)
++      memcpy(safe_palette, palette, (unsigned int)num_palette *
++          (sizeof (png_color)));
++
++   palette = safe_palette;
++
+    png_free_data(png_ptr, info_ptr, PNG_FREE_PLTE, 0);
+ 
+    /* Changed in libpng-1.2.1 to allocate PNG_MAX_PALETTE_LENGTH instead
+@@ -1000,6 +1017,16 @@ png_set_tRNS(png_structrp png_ptr, png_inforp info_ptr,
+ 
+    if (trans_alpha != NULL)
+    {
++       /* Snapshot the caller's trans_alpha before freeing, in case it
++        * points to info_ptr->trans_alpha (getter-to-setter aliasing).
++        */
++       png_byte safe_trans[PNG_MAX_PALETTE_LENGTH];
++
++       if (num_trans > 0 && num_trans <= PNG_MAX_PALETTE_LENGTH)
++          memcpy(safe_trans, trans_alpha, (size_t)num_trans);
++
++       trans_alpha = safe_trans;
++
+        png_free_data(png_ptr, info_ptr, PNG_FREE_TRNS, 0);
+ 
+        if (num_trans > 0 && num_trans <= PNG_MAX_PALETTE_LENGTH)
+diff --git a/tests/pnggetset b/tests/pnggetset
+new file mode 100755
+index 000000000..57ef731a5
+--- /dev/null
++++ b/tests/pnggetset
+@@ -0,0 +1,5 @@
++#!/bin/sh
++
++# pnggetset test:
++# Getter-to-setter roundtrips for various chunk types.
++exec ./pnggetset
+-- 
+2.51.0
+
diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch
new file mode 100644
index 00000000000..7d58ead18de
--- /dev/null
+++ b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch
@@ -0,0 +1,484 @@
+From 2d1c6585d356832bb679ad4d313f5ea542e02064 Mon Sep 17 00:00:00 2001
+From: Cosmin Truta <ctruta@gmail.com>
+Date: Mon, 30 Mar 2026 17:43:05 +0300
+Subject: [PATCH] fix: Handle getter-to-setter aliasing in append-style
+ chunk setters
+
+Apply the same class of robustness fix from the previous commit to
+`png_set_text`, `png_set_sPLT` and `png_set_unknown_chunks`. These
+append-style setters used `png_realloc_array` to grow the internal
+array, then freed the old array before copying from the caller's
+input. If the caller's pointer was obtained from the corresponding
+getter, it aliased the freed array.
+
+The fix defers the freeing of the old array until after the copy loop.
+
+Also extend the pnggetset regression test to cover all three setters.
+
+CVE: CVE-2026-34757
+Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc]
+
+(cherry picked from commit 55d20aaa322c9274491cda82c5cd4f99b48c6bcc)
+Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
+---
+ contrib/libtests/pnggetset.c | 330 ++++++++++++++++++++++++++++++++++-
+ pngset.c                     |  25 ++-
+ 2 files changed, 347 insertions(+), 8 deletions(-)
+
+diff --git a/contrib/libtests/pnggetset.c b/contrib/libtests/pnggetset.c
+index b42508094..6ae43dc66 100644
+--- a/contrib/libtests/pnggetset.c
++++ b/contrib/libtests/pnggetset.c
+@@ -6,12 +6,12 @@
+  * For conditions of distribution and use, see the disclaimer
+  * and license in png.h
+  *
+- * Test the get-then-set roundtrip pattern for PLTE, tRNS, and hIST.
++ * Test the get-then-set roundtrip for chunk types whose getters return
++ * a pointer to internal storage.
+  *
+- * Passing the internal pointer returned by a getter back into the
+- * corresponding setter is a natural API usage pattern.  A previous
+- * version had a use-after-free on this path because the setter freed
+- * the internal buffer before copying from the caller-supplied pointer.
++ * Passing such a pointer back into the corresponding setter must not
++ * cause a use-after-free.  A previous version freed the internal buffer
++ * before copying from the caller-supplied pointer.
+  */
+ 
+ #include <stdio.h>
+@@ -285,6 +285,290 @@ test_trns_roundtrip(void)
+ }
+ #endif /* PNG_tRNS_SUPPORTED */
+ 
++#ifdef PNG_TEXT_SUPPORTED
++/* Test: get the text array, pass it straight back to set, verify data. */
++#define TEXT_COUNT 6 /* enough to trigger reallocation on the second set */
++static int
++test_text_roundtrip(void)
++{
++   png_structp png_ptr;
++   png_infop info_ptr;
++   png_text text_entries[TEXT_COUNT];
++   png_textp got_text = NULL;
++   int got_num_text = 0;
++   int i;
++
++   /* Recognizable keys and values. */
++   static const char *keys[TEXT_COUNT] = {
++      "Title", "Author", "Desc", "Copyright", "Source", "Comment"
++   };
++   static const char *vals[TEXT_COUNT] = {
++      "t0", "t1", "t2", "t3", "t4", "t5"
++   };
++
++   png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++       NULL, NULL, NULL);
++   if (png_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++      return 1;
++   }
++
++   info_ptr = png_create_info_struct(png_ptr);
++   if (info_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++      png_destroy_write_struct(&png_ptr, NULL);
++      return 1;
++   }
++
++   if (setjmp(png_jmpbuf(png_ptr)))
++   {
++      fprintf(stderr, "pnggetset: libpng error in test_text_roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* Populate the text entries. */
++   memset(text_entries, 0, sizeof text_entries);
++   for (i = 0; i < TEXT_COUNT; i++)
++   {
++      text_entries[i].compression = PNG_TEXT_COMPRESSION_NONE;
++      text_entries[i].key = (png_charp)keys[i];
++      text_entries[i].text = (png_charp)vals[i];
++   }
++   png_set_text(png_ptr, info_ptr, text_entries, TEXT_COUNT);
++
++   /* Get the internal pointer and feed it straight back (append). */
++   png_get_text(png_ptr, info_ptr, &got_text, &got_num_text);
++   if (got_text == NULL || got_num_text != TEXT_COUNT)
++   {
++      fprintf(stderr, "pnggetset: png_get_text returned unexpected values\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* This is the critical call: got_text aliases info_ptr->text. */
++   png_set_text(png_ptr, info_ptr, got_text, got_num_text);
++
++   /* Verify the original entries survived. */
++   got_text = NULL;
++   got_num_text = 0;
++   png_get_text(png_ptr, info_ptr, &got_text, &got_num_text);
++   if (got_text == NULL || got_num_text != TEXT_COUNT * 2)
++   {
++      fprintf(stderr, "pnggetset: text count %d, expected %d after roundtrip\n",
++          got_num_text, TEXT_COUNT * 2);
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++   for (i = 0; i < TEXT_COUNT; i++)
++   {
++      if (got_text[i].key == NULL ||
++          strcmp(got_text[i].key, keys[i]) != 0 ||
++          got_text[i].text == NULL ||
++          strcmp(got_text[i].text, vals[i]) != 0)
++      {
++         fprintf(stderr,
++             "pnggetset: text entry %d corrupted after roundtrip\n", i);
++         png_destroy_write_struct(&png_ptr, &info_ptr);
++         return 1;
++      }
++   }
++
++   png_destroy_write_struct(&png_ptr, &info_ptr);
++   return 0;
++}
++#undef TEXT_COUNT
++#endif /* PNG_TEXT_SUPPORTED */
++
++#ifdef PNG_sPLT_SUPPORTED
++/* Test: get the sPLT array, pass it straight back to set, verify data. */
++static int
++test_splt_roundtrip(void)
++{
++   png_structp png_ptr;
++   png_infop info_ptr;
++   png_sPLT_t splt;
++   png_sPLT_entry splt_entries[4];
++   png_sPLT_tp got_spalettes = NULL;
++   int got_num, i;
++
++   png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++       NULL, NULL, NULL);
++   if (png_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++      return 1;
++   }
++
++   info_ptr = png_create_info_struct(png_ptr);
++   if (info_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++      png_destroy_write_struct(&png_ptr, NULL);
++      return 1;
++   }
++
++   if (setjmp(png_jmpbuf(png_ptr)))
++   {
++      fprintf(stderr, "pnggetset: libpng error in test_splt_roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* Populate with recognizable values. */
++   memset(splt_entries, 0, sizeof splt_entries);
++   for (i = 0; i < 4; i++)
++   {
++      splt_entries[i].red = (png_uint_16)(i * 1000);
++      splt_entries[i].green = (png_uint_16)(i * 2000);
++      splt_entries[i].blue = (png_uint_16)(i * 3000);
++      splt_entries[i].alpha = 0xffffU;
++      splt_entries[i].frequency = (png_uint_16)(i + 1);
++   }
++   memset(&splt, 0, sizeof splt);
++   splt.name = (png_charp)"test_sPLT";
++   splt.depth = 16;
++   splt.entries = splt_entries;
++   splt.nentries = 4;
++
++   png_set_sPLT(png_ptr, info_ptr, &splt, 1);
++
++   /* Get the internal pointer and feed it straight back (append). */
++   got_num = png_get_sPLT(png_ptr, info_ptr, &got_spalettes);
++   if (got_spalettes == NULL || got_num != 1)
++   {
++      fprintf(stderr, "pnggetset: png_get_sPLT returned unexpected values\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* This is the critical call: got_spalettes aliases internal storage. */
++   png_set_sPLT(png_ptr, info_ptr, got_spalettes, got_num);
++
++   /* Verify the original entry survived. */
++   got_spalettes = NULL;
++   got_num = png_get_sPLT(png_ptr, info_ptr, &got_spalettes);
++   if (got_spalettes == NULL || got_num != 2)
++   {
++      fprintf(stderr, "pnggetset: sPLT count %d, expected 2 after roundtrip\n",
++          got_num);
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++   if (strcmp(got_spalettes[0].name, "test_sPLT") != 0 ||
++       got_spalettes[0].nentries != 4 ||
++       got_spalettes[0].depth != 16)
++   {
++      fprintf(stderr,
++          "pnggetset: sPLT entry 0 corrupted after roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++   for (i = 0; i < 4; i++)
++   {
++      if (got_spalettes[0].entries[i].red != (png_uint_16)(i * 1000) ||
++          got_spalettes[0].entries[i].green != (png_uint_16)(i * 2000) ||
++          got_spalettes[0].entries[i].blue != (png_uint_16)(i * 3000))
++      {
++         fprintf(stderr,
++             "pnggetset: sPLT[0] entry %d corrupted after roundtrip\n", i);
++         png_destroy_write_struct(&png_ptr, &info_ptr);
++         return 1;
++      }
++   }
++
++   png_destroy_write_struct(&png_ptr, &info_ptr);
++   return 0;
++}
++#endif /* PNG_sPLT_SUPPORTED */
++
++#ifdef PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED
++/* Test: get unknown chunks, pass them straight back to set, verify data. */
++static int
++test_unknown_roundtrip(void)
++{
++   png_structp png_ptr;
++   png_infop info_ptr;
++   png_unknown_chunk unk;
++   png_unknown_chunkp got_unknowns = NULL;
++   int got_num;
++   static const png_byte test_data[] = {0xde, 0xad, 0xbe, 0xef};
++
++   png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++       NULL, NULL, NULL);
++   if (png_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++      return 1;
++   }
++
++   info_ptr = png_create_info_struct(png_ptr);
++   if (info_ptr == NULL)
++   {
++      fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++      png_destroy_write_struct(&png_ptr, NULL);
++      return 1;
++   }
++
++   if (setjmp(png_jmpbuf(png_ptr)))
++   {
++      fprintf(stderr,
++          "pnggetset: libpng error in test_unknown_roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* Set up an unknown chunk with recognizable data. */
++   memset(&unk, 0, sizeof unk);
++   memcpy(unk.name, "teSt", 5);
++   unk.data = (png_bytep)test_data;
++   unk.size = sizeof test_data;
++   unk.location = PNG_HAVE_IHDR;
++
++   png_set_keep_unknown_chunks(png_ptr, PNG_HANDLE_CHUNK_ALWAYS, NULL, 0);
++   png_set_unknown_chunks(png_ptr, info_ptr, &unk, 1);
++
++   /* Get the internal pointer and feed it straight back (append). */
++   got_num = png_get_unknown_chunks(png_ptr, info_ptr, &got_unknowns);
++   if (got_unknowns == NULL || got_num != 1)
++   {
++      fprintf(stderr,
++          "pnggetset: png_get_unknown_chunks returned unexpected values\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   /* This is the critical call: got_unknowns aliases internal storage. */
++   png_set_unknown_chunks(png_ptr, info_ptr, got_unknowns, got_num);
++
++   /* Verify the original entry survived. */
++   got_unknowns = NULL;
++   got_num = png_get_unknown_chunks(png_ptr, info_ptr, &got_unknowns);
++   if (got_unknowns == NULL || got_num != 2)
++   {
++      fprintf(stderr,
++          "pnggetset: unknown_chunks count %d, expected 2 after roundtrip\n",
++          got_num);
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++   if (memcmp(got_unknowns[0].name, "teSt", 4) != 0 ||
++       got_unknowns[0].size != sizeof test_data ||
++       memcmp(got_unknowns[0].data, test_data, sizeof test_data) != 0)
++   {
++      fprintf(stderr,
++          "pnggetset: unknown chunk 0 corrupted after roundtrip\n");
++      png_destroy_write_struct(&png_ptr, &info_ptr);
++      return 1;
++   }
++
++   png_destroy_write_struct(&png_ptr, &info_ptr);
++   return 0;
++}
++#endif /* PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED */
++
+ int
+ main(void)
+ {
+@@ -324,5 +608,41 @@ main(void)
+       printf("PASS\n");
+ #endif
+ 
++#ifdef PNG_TEXT_SUPPORTED
++   printf("Testing tEXt get-then-set roundtrip... ");
++   fflush(stdout);
++   if (test_text_roundtrip() != 0)
++   {
++      printf("FAIL\n");
++      result = 1;
++   }
++   else
++      printf("PASS\n");
++#endif
++
++#ifdef PNG_sPLT_SUPPORTED
++   printf("Testing sPLT get-then-set roundtrip... ");
++   fflush(stdout);
++   if (test_splt_roundtrip() != 0)
++   {
++      printf("FAIL\n");
++      result = 1;
++   }
++   else
++      printf("PASS\n");
++#endif
++
++#ifdef PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED
++   printf("Testing unknown chunks get-then-set roundtrip... ");
++   fflush(stdout);
++   if (test_unknown_roundtrip() != 0)
++   {
++      printf("FAIL\n");
++      result = 1;
++   }
++   else
++      printf("PASS\n");
++#endif
++
+    return result;
+ }
+diff --git a/pngset.c b/pngset.c
+index 9f5c44510..9ffaf2b5a 100644
+--- a/pngset.c
++++ b/pngset.c
+@@ -789,6 +789,7 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr,
+     png_const_textp text_ptr, int num_text)
+ {
+    int i;
++   png_textp old_text = NULL;
+ 
+    png_debug1(1, "in text storage function, chunk typeid = 0x%lx",
+       png_ptr == NULL ? 0xabadca11UL : (unsigned long)png_ptr->chunk_name);
+@@ -836,7 +837,10 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr,
+          return 1;
+       }
+ 
+-      png_free(png_ptr, info_ptr->text);
++      /* Defer freeing the old array until after the copy loop below,
++       * in case text_ptr aliases info_ptr->text (getter-to-setter).
++       */
++      old_text = info_ptr->text;
+ 
+       info_ptr->text = new_text;
+       info_ptr->free_me |= PNG_FREE_TEXT;
+@@ -921,6 +925,7 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr,
+       {
+          png_chunk_report(png_ptr, "text chunk: out of memory",
+              PNG_CHUNK_WRITE_ERROR);
++         png_free(png_ptr, old_text);
+ 
+          return 1;
+       }
+@@ -974,6 +979,8 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr,
+       png_debug1(3, "transferred text chunk %d", info_ptr->num_text);
+    }
+ 
++   png_free(png_ptr, old_text);
++
+    return 0;
+ }
+ #endif
+@@ -1112,6 +1119,7 @@ png_set_sPLT(png_const_structrp png_ptr,
+  */
+ {
+    png_sPLT_tp np;
++   png_sPLT_tp old_spalettes;
+ 
+    png_debug1(1, "in %s storage function", "sPLT");
+ 
+@@ -1132,7 +1140,10 @@ png_set_sPLT(png_const_structrp png_ptr,
+       return;
+    }
+ 
+-   png_free(png_ptr, info_ptr->splt_palettes);
++   /* Defer freeing the old array until after the copy loop below,
++    * in case entries aliases info_ptr->splt_palettes (getter-to-setter).
++    */
++   old_spalettes = info_ptr->splt_palettes;
+ 
+    info_ptr->splt_palettes = np;
+    info_ptr->free_me |= PNG_FREE_SPLT;
+@@ -1196,6 +1207,8 @@ png_set_sPLT(png_const_structrp png_ptr,
+    }
+    while (--nentries);
+ 
++   png_free(png_ptr, old_spalettes);
++
+    if (nentries > 0)
+       png_chunk_report(png_ptr, "sPLT out of memory", PNG_CHUNK_WRITE_ERROR);
+ }
+@@ -1244,6 +1257,7 @@ png_set_unknown_chunks(png_const_structrp png_ptr,
+     png_inforp info_ptr, png_const_unknown_chunkp unknowns, int num_unknowns)
+ {
+    png_unknown_chunkp np;
++   png_unknown_chunkp old_unknowns;
+ 
+    if (png_ptr == NULL || info_ptr == NULL || num_unknowns <= 0 ||
+        unknowns == NULL)
+@@ -1290,7 +1304,10 @@ png_set_unknown_chunks(png_const_structrp png_ptr,
+       return;
+    }
+ 
+-   png_free(png_ptr, info_ptr->unknown_chunks);
++   /* Defer freeing the old array until after the copy loop below,
++    * in case unknowns aliases info_ptr->unknown_chunks (getter-to-setter).
++    */
++   old_unknowns = info_ptr->unknown_chunks;
+ 
+    info_ptr->unknown_chunks = np; /* safe because it is initialized */
+    info_ptr->free_me |= PNG_FREE_UNKN;
+@@ -1336,6 +1353,8 @@ png_set_unknown_chunks(png_const_structrp png_ptr,
+       ++np;
+       ++(info_ptr->unknown_chunks_num);
+    }
++
++   png_free(png_ptr, old_unknowns);
+ }
+ 
+ void PNGAPI
+-- 
+2.51.0
+
diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.42.bb b/meta/recipes-multimedia/libpng/libpng_1.6.42.bb
index e4cc63686e9..b226e327b64 100644
--- a/meta/recipes-multimedia/libpng/libpng_1.6.42.bb
+++ b/meta/recipes-multimedia/libpng/libpng_1.6.42.bb
@@ -29,6 +29,8 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/${PV}/${BP}.tar.xz
            file://CVE-2026-33416-02.patch \
            file://CVE-2026-33416-03.patch \
            file://CVE-2026-33416-04.patch \
+           file://CVE-2026-34757_p1.patch \
+           file://CVE-2026-34757_p2.patch \
 "
 
 SRC_URI[sha256sum] = "c919dbc11f4c03b05aba3f8884d8eb7adfe3572ad228af972bb60057bdb48450"
@@ -66,7 +68,7 @@ do_install_ptest() {
     install -m 644 ${S}/contrib/tools/*.c ${S}/contrib/tools/*.h ${D}${PTEST_PATH}/src/contrib/tools
 
     # Install .libs directory binaries to ptest path
-    install -m 755 ${B}/.libs/pngtest ${B}/.libs/pngstest ${B}/.libs/pngimage ${B}/.libs/pngunknown ${B}/.libs/pngvalid ${D}${PTEST_PATH}/src
+    install -m 755 ${B}/.libs/pngtest ${B}/.libs/pnggetset ${B}/.libs/pngstest ${B}/.libs/pngimage ${B}/.libs/pngunknown ${B}/.libs/pngvalid ${D}${PTEST_PATH}/src
 
     # Copy png files to ptest path
     cd ${S} && find contrib -name '*.png' | cpio -pd ${D}${PTEST_PATH}/src


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 25/31] glib-2.0: fix CVE-2026-58010
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (23 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 24/31] libpng: Fix CVE-2026-34757 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 26/31] glib-2.0: fix CVE-2026-58011 Yoann Congal
                   ` (5 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

This patch applies the upstream 2.86.5 backport for
CVE-2026-58010. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58010

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../glib-2.0/glib-2.0/CVE-2026-58010.patch    | 113 ++++++++++++++++++
 meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |   1 +
 2 files changed, 114 insertions(+)
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch

diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
new file mode 100644
index 00000000000..842d53af5cf
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
@@ -0,0 +1,113 @@
+From 333f164f00fb874e3c670ce70d2a2a3667b9ebf9 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Sun, 29 Mar 2026 19:10:41 +0100
+Subject: [PATCH] gvariant: Fix an off-by-one error in an offset comparison
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+This allows a single byte out-of-bounds read off the end of the
+(potentially untrusted) byte array backing a `GVariant` when it’s
+being checked for normal form.
+
+I can’t see how this could practically be exploited, but it’s certainly
+a security bug as the `GVariant` normal form checking code is supposed
+to be robust to malicious inputs.
+
+Spotted by linhlhq as #YWH-PGM9867-190, and fix and reproducer provided
+by them too, thanks. Confirmed and turned into a unit test by me.
+
+Fixes: #3915
+
+CVE: CVE-2026-58010
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit aa1cb87d56111ef989811e824f0ac77484cc997f)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/gvariant-serialiser.c |  2 +-
+ glib/tests/gvariant.c      | 48 ++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 49 insertions(+), 1 deletion(-)
+
+diff --git a/glib/gvariant-serialiser.c b/glib/gvariant-serialiser.c
+index 4e4a73ad1..99a1d3fbd 100644
+--- a/glib/gvariant-serialiser.c
++++ b/glib/gvariant-serialiser.c
+@@ -1247,7 +1247,7 @@ gvs_tuple_is_normal (GVariantSerialised value)
+ 
+       while (offset & alignment)
+         {
+-          if (offset > value.size || value.data[offset] != '\0')
++          if (offset >= value.size || value.data[offset] != '\0')
+             return FALSE;
+           offset++;
+         }
+diff --git a/glib/tests/gvariant.c b/glib/tests/gvariant.c
+index c8f13360c..55e2cee00 100644
+--- a/glib/tests/gvariant.c
++++ b/glib/tests/gvariant.c
+@@ -5637,6 +5637,52 @@ test_normal_checking_tuple_offsets5 (void)
+   g_variant_unref (variant);
+ }
+ 
++/* This is a regression test that looping over the padding bytes in a short
++ * (non-normal) tuple doesn’t overflow the input data.
++ *
++ * See https://gitlab.gnome.org/GNOME/glib/-/issues/3915 */
++static void
++test_normal_checking_tuple_offsets6 (void)
++{
++  /*
++   * Type: (ynqiuxthdsog) — 12 members, first member 'y' (byte) has
++   * alignment 0, second 'n' (int16) has alignment 1.
++   * With 1 byte of data (0x28), after reading the first byte member,
++   * offset=1, alignment check for 'n' requires offset to be even,
++   * so the while loop checks value.data[1] — but size is only 1.
++   *
++   * Use heap allocation via GBytes so ASan reports heap-buffer-overflow.
++   */
++  guint8 *heap_data = NULL;
++  GBytes *bytes = NULL;
++  const GVariantType *data_type = G_VARIANT_TYPE ("(ynqiuxthdsog)");
++  GVariant *variant = NULL;
++  GVariant *normal_variant = NULL;
++  GVariant *expected = NULL;
++
++  g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3915");
++
++  heap_data = g_malloc (1);
++  heap_data[0] = 0x28;
++  bytes = g_bytes_new_take (heap_data, 1);
++
++  variant = g_variant_new_from_bytes (data_type, bytes, FALSE);
++  g_assert_nonnull (variant);
++
++  g_assert_false (g_variant_is_normal_form (variant));
++
++  normal_variant = g_variant_get_normal_form (variant);
++  g_assert_nonnull (normal_variant);
++
++  expected = g_variant_new_parsed ("(byte 0x28, int16 0, uint16 0, 0, uint32 0, int64 0, uint64 0, handle 0, 0.0, '', objectpath '/', signature '')");
++  g_assert_cmpvariant (expected, variant);
++  g_assert_cmpvariant (expected, normal_variant);
++
++  g_variant_unref (expected);
++  g_variant_unref (normal_variant);
++  g_variant_unref (variant);
++}
++
+ /* Test that an otherwise-valid serialised GVariant is considered non-normal if
+  * its offset table entries are too wide.
+  *
+@@ -5890,6 +5936,8 @@ main (int argc, char **argv)
+                    test_normal_checking_tuple_offsets4);
+   g_test_add_func ("/gvariant/normal-checking/tuple-offsets5",
+                    test_normal_checking_tuple_offsets5);
++  g_test_add_func ("/gvariant/normal-checking/tuple-offsets6",
++                   test_normal_checking_tuple_offsets6);
+   g_test_add_func ("/gvariant/normal-checking/tuple-offsets/minimal-sized",
+                    test_normal_checking_tuple_offsets_minimal_sized);
+   g_test_add_func ("/gvariant/normal-checking/empty-object-path",
+-- 
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 549584f3d8f..54691690117 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -49,6 +49,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
            file://CVE-2026-1489-04.patch \
            file://CVE-2026-58016-1.patch \
            file://CVE-2026-58016-2.patch \
+           file://CVE-2026-58010.patch \
            "
 SRC_URI:append:class-native = " file://relocate-modules.patch \
                                 file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 26/31] glib-2.0: fix CVE-2026-58011
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (24 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 25/31] glib-2.0: fix CVE-2026-58010 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 27/31] glib-2.0: fix CVE-2026-58012 Yoann Congal
                   ` (4 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

This patch applies the upstream 2.86.5 backport for
CVE-2026-58011. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://gitlab.gnome.org/GNOME/glib/-/commit/ae27363f025ffc131e2d75ee88a5cd8320dffe3b
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58011

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../glib-2.0/glib-2.0/CVE-2026-58011.patch    | 78 +++++++++++++++++++
 meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |  1 +
 2 files changed, 79 insertions(+)
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch

diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
new file mode 100644
index 00000000000..a8d31c1270c
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
@@ -0,0 +1,78 @@
+From 371dbccb6b9a9a42b93c4b371214b159e7e94792 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Sun, 29 Mar 2026 23:46:17 +0100
+Subject: [PATCH] gdatetime: Add missing range validation to
+ g_date_time_add_full()
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Otherwise it’s possible to create a non-`NULL` but invalid `GDateTime`,
+which breaks all kinds of internal assumptions.
+
+Spotted by linhlhq as #YWH-PGM9867-191. Thanks to them for providing a
+suggested fix and a test case, which I have adapted and validated.
+
+Fixes: #3917
+
+CVE: CVE-2026-58011
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/ae27363f025ffc131e2d75ee88a5cd8320dffe3b]
+
+Backport Changes:
+- Used the target branch's existing literal day bounds because it does
+  not have upstream's MIN_DAYS/MAX_DAYS helper macros.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit ae27363f025ffc131e2d75ee88a5cd8320dffe3b)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/gdatetime.c       |  4 +++-
+ glib/tests/gdatetime.c | 18 ++++++++++++++++++
+ 2 files changed, 21 insertions(+), 1 deletion(-)
+
+diff --git a/glib/gdatetime.c b/glib/gdatetime.c
+index 2640e3b24..73eea643b 100644
+--- a/glib/gdatetime.c
++++ b/glib/gdatetime.c
+@@ -2024,7 +2024,9 @@ g_date_time_add_full (GDateTime *datetime,
+   new->days = full_time / USEC_PER_DAY;
+   new->usec = full_time % USEC_PER_DAY;
+ 
+-  /* XXX validate */
++  /* Validate it’s still in the range 0001-01-01 to 9999-12-31 */
++  if (new->days < 1 || new->days > 3652059)
++    g_clear_pointer (&new, g_date_time_unref);
+ 
+   return new;
+ }
+diff --git a/glib/tests/gdatetime.c b/glib/tests/gdatetime.c
+index 49390c900..527d61a11 100644
+--- a/glib/tests/gdatetime.c
++++ b/glib/tests/gdatetime.c
+@@ -1117,6 +1117,24 @@ test_GDateTime_add_full (void)
+   TEST_ADD_FULL (2010,  8, 25, 22, 45, 0,
+                     0,  1,  6,  1, 25, 0,
+                  2010, 10,  2,  0, 10, 0);
++
++#define TEST_ADD_FULL_ERROR(y,m,d,h,mi,s,ay,am,ad,ah,ami,as) G_STMT_START { \
++  GDateTime *dt; \
++  dt = g_date_time_new_utc (y, m, d, h, mi, s); \
++  g_assert_null (g_date_time_add_full (dt, ay, am, ad, ah, ami, as)); \
++  g_date_time_unref (dt); \
++} G_STMT_END
++
++  TEST_ADD_FULL_ERROR (     1, 12,  1,  0,  0, 0,
++                           -1,  0,  0,  0,  0, 0);
++  TEST_ADD_FULL_ERROR (     1, 12,  1,  0,  0, 0,
++                        10000,  0,  0,  0,  0, 0);
++  TEST_ADD_FULL_ERROR (  9999, 12,  1,  0,  0, 0,
++                       -10000,  0,  0,  0,  0, 0);
++  TEST_ADD_FULL_ERROR (     1, 12,  1,  0,  0, 0,
++                            0,  0, 3660001,  0,  0, 0);
++  TEST_ADD_FULL_ERROR (  9999, 12,  1,  0,  0, 0,
++                            0,  0, -3660001,  0,  0, 0);
+ }
+ 
+ static void
+-- 
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 54691690117..a2de973e218 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -50,6 +50,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
            file://CVE-2026-58016-1.patch \
            file://CVE-2026-58016-2.patch \
            file://CVE-2026-58010.patch \
+           file://CVE-2026-58011.patch \
            "
 SRC_URI:append:class-native = " file://relocate-modules.patch \
                                 file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 27/31] glib-2.0: fix CVE-2026-58012
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (25 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 26/31] glib-2.0: fix CVE-2026-58011 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 28/31] glib-2.0: fix CVE-2026-58013 Yoann Congal
                   ` (3 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

This patch applies the upstream 2.86.5 backport for
CVE-2026-58012. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://gitlab.gnome.org/GNOME/glib/-/commit/d337aabd24ee2b8ac2a690dba3ccf26aa70e638f
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58012

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../glib-2.0/glib-2.0/CVE-2026-58012.patch    | 228 ++++++++++++++++++
 meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |   1 +
 2 files changed, 229 insertions(+)
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch

diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
new file mode 100644
index 00000000000..7f8435809c6
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
@@ -0,0 +1,228 @@
+From 74564fefcec22fc1efc187c36aa1fb8dcfe34454 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 31 Mar 2026 16:13:57 +0100
+Subject: [PATCH] gregex: Fix case changing substitutions with G_REGEX_RAW
+
+In `G_REGEX_RAW` mode, the input string is treated as a byte array
+(basically ASCII) rather than a unichar array. Accordingly, the case
+changing code for substitutions needs to operate on bytes with
+`G_REGEX_RAW`, rather than operating on unichars.
+
+This fixes a potential buffer overflow when trying to do a case change
+on a match of a set of bytes which are a truncated multi-byte UTF-8
+encoding at the end of the input buffer.
+
+Spotted by linhlhq as #YWH-PGM9867-193. I adapted their reproducer as
+the unit test, but implemented the fix in `gregex.c` independently.
+
+Fixes: #3918
+
+CVE: CVE-2026-58012
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/d337aabd24ee2b8ac2a690dba3ccf26aa70e638f]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit d337aabd24ee2b8ac2a690dba3ccf26aa70e638f)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/gregex.c      | 59 ++++++++++++++++++++++++++++++++++------------
+ glib/tests/regex.c | 53 +++++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 97 insertions(+), 15 deletions(-)
+
+diff --git a/glib/gregex.c b/glib/gregex.c
+index 116ecacbb..496b34bbd 100644
+--- a/glib/gregex.c
++++ b/glib/gregex.c
+@@ -3147,19 +3147,25 @@ split_replacement (const gchar  *replacement,
+   return g_list_reverse (list);
+ }
+ 
+-/* Change the case of c based on change_case. */
+-#define CHANGE_CASE(c, change_case) \
++/* Change the case of c based on change_case.
++ * g_ascii_to*() will happily pass through non-ASCII bytes unchanged. */
++#define UTF8_CHANGE_CASE(c, change_case) \
+         (((change_case) & CHANGE_CASE_LOWER_MASK) ? \
+                 g_unichar_tolower (c) : \
+                 g_unichar_toupper (c))
++#define RAW_CHANGE_CASE(c, change_case) \
++        (((change_case) & CHANGE_CASE_LOWER_MASK) ? \
++                g_ascii_tolower (c) : \
++                g_ascii_toupper (c))
+ 
++/* If @text_is_raw is set, @text might not be valid UTF-8 (but will be
++ * nul-terminated). */
+ static void
+ string_append (GString     *string,
+                const gchar *text,
++               gboolean     text_is_raw,
+                ChangeCase  *change_case)
+ {
+-  gunichar c;
+-
+   if (text[0] == '\0')
+     return;
+ 
+@@ -3169,22 +3175,44 @@ string_append (GString     *string,
+     }
+   else if (*change_case & CHANGE_CASE_SINGLE_MASK)
+     {
+-      c = g_utf8_get_char (text);
+-      g_string_append_unichar (string, CHANGE_CASE (c, *change_case));
+-      g_string_append (string, g_utf8_next_char (text));
++      if (!text_is_raw)
++        {
++          gunichar c = g_utf8_get_char (text);
++          g_string_append_unichar (string, UTF8_CHANGE_CASE (c, *change_case));
++          g_string_append (string, g_utf8_next_char (text));
++        }
++      else
++        {
++          g_string_append_c (string, RAW_CHANGE_CASE (text[0], *change_case));
++          g_string_append (string, text + 1);
++        }
++
+       *change_case = CHANGE_CASE_NONE;
+     }
+   else
+     {
+-      while (*text != '\0')
++      if (!text_is_raw)
+         {
+-          c = g_utf8_get_char (text);
+-          g_string_append_unichar (string, CHANGE_CASE (c, *change_case));
+-          text = g_utf8_next_char (text);
++          while (*text != '\0')
++            {
++              gunichar c = g_utf8_get_char (text);
++              g_string_append_unichar (string, UTF8_CHANGE_CASE (c, *change_case));
++              text = g_utf8_next_char (text);
++            }
++        }
++      else
++        {
++          while (*text != '\0')
++            {
++              char c = *text;
++              g_string_append_c (string, RAW_CHANGE_CASE (c, *change_case));
++              text++;
++            }
+         }
+     }
+ }
+ 
++/* @match_info is (nullable) */
+ static gboolean
+ interpolate_replacement (const GMatchInfo *match_info,
+                          GString          *result,
+@@ -3194,6 +3222,7 @@ interpolate_replacement (const GMatchInfo *match_info,
+   InterpolationData *idata;
+   gchar *match;
+   ChangeCase change_case = CHANGE_CASE_NONE;
++  gboolean is_raw = (match_info != NULL && (match_info->regex->orig_compile_opts & G_REGEX_RAW));
+ 
+   for (list = data; list; list = list->next)
+     {
+@@ -3201,10 +3230,10 @@ interpolate_replacement (const GMatchInfo *match_info,
+       switch (idata->type)
+         {
+         case REPL_TYPE_STRING:
+-          string_append (result, idata->text, &change_case);
++          string_append (result, idata->text, is_raw, &change_case);
+           break;
+         case REPL_TYPE_CHARACTER:
+-          g_string_append_c (result, CHANGE_CASE (idata->c, change_case));
++          g_string_append_c (result, UTF8_CHANGE_CASE (idata->c, change_case));
+           if (change_case & CHANGE_CASE_SINGLE_MASK)
+             change_case = CHANGE_CASE_NONE;
+           break;
+@@ -3212,7 +3241,7 @@ interpolate_replacement (const GMatchInfo *match_info,
+           match = g_match_info_fetch (match_info, idata->num);
+           if (match)
+             {
+-              string_append (result, match, &change_case);
++              string_append (result, match, is_raw, &change_case);
+               g_free (match);
+             }
+           break;
+@@ -3220,7 +3249,7 @@ interpolate_replacement (const GMatchInfo *match_info,
+           match = g_match_info_fetch_named (match_info, idata->text);
+           if (match)
+             {
+-              string_append (result, match, &change_case);
++              string_append (result, match, is_raw, &change_case);
+               g_free (match);
+             }
+           break;
+diff --git a/glib/tests/regex.c b/glib/tests/regex.c
+index d7a698ec6..bffb52a87 100644
+--- a/glib/tests/regex.c
++++ b/glib/tests/regex.c
+@@ -2529,6 +2529,58 @@ test_compiled_regex_after_jit_failure (void)
+   g_regex_unref (regex);
+ }
+ 
++static void
++test_replace_raw_change_case (void)
++{
++  GError *local_error = NULL;
++  GRegex *regex = NULL;
++
++  g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3918");
++  g_test_summary ("Test that case changes as part of a replacement are handled correctly in G_REGEX_RAW mode");
++
++  /*
++   * Match a multi-byte sequence in RAW mode. The pattern matches
++   * exactly 2 bytes. The subject contains a 4-byte UTF-8 lead (0xF4)
++   * followed by only one continuation byte, then NUL.
++   *
++   * The matched substring will be "\xf4\x80" (2 bytes, heap-allocated
++   * as 3-byte buffer with NUL). If the code regresses and tries to handle
++   * the replacement as UTF-8 then g_utf8_get_char() would see 0xF4 and try
++   * to read 4 bytes, going 1 byte past the NUL into OOB territory.
++   */
++  regex = g_regex_new ("..", G_REGEX_RAW, 0, &local_error);
++  g_assert_no_error (local_error);
++
++  /*
++   * Build a subject string with truncated UTF-8.
++   * \xF4 = 4-byte UTF-8 lead byte
++   * \x80 = continuation byte
++   * No 3rd/4th continuation bytes — the match is only 2 bytes.
++   *
++   * \U\0 = uppercase the entire match → triggers string_append()
++   * with case change on the 2-byte non-UTF-8 match.
++   */
++  char subject[] = "\xf4\x80";
++  char *result = g_regex_replace (regex, subject, -1, 0, "\\U\\0", 0, &local_error);
++  g_assert_no_error (local_error);
++
++  g_clear_pointer (&result, g_free);
++  g_clear_pointer (&regex, g_regex_unref);
++
++  /*
++   * Second variant: single-char case change \u with \0 backreference.
++   */
++  regex = g_regex_new (".", G_REGEX_RAW, 0, &local_error);
++  g_assert_no_error (local_error);
++
++  char subject2[] = "\xe6\xb0";  /* 3-byte UTF-8 lead, only 2 bytes */
++  result = g_regex_replace (regex, subject2, -1, 0, "\\u\\0", 0, &local_error);
++  g_assert_no_error (local_error);
++
++  g_clear_pointer (&result, g_free);
++  g_clear_pointer (&regex, g_regex_unref);
++}
++
+ int
+ main (int argc, char *argv[])
+ {
+@@ -2550,6 +2602,7 @@ main (int argc, char *argv[])
+   g_test_add_func ("/regex/jit-unsupported-matching", test_jit_unsupported_matching_options);
+   g_test_add_func ("/regex/unmatched-named-subpattern", test_unmatched_named_subpattern);
+   g_test_add_func ("/regex/compiled-regex-after-jit-failure", test_compiled_regex_after_jit_failure);
++  g_test_add_func ("/regex/replace-raw-change-case", test_replace_raw_change_case);
+ 
+   /* TEST_NEW(pattern, compile_opts, match_opts) */
+   TEST_NEW("[A-Z]+", G_REGEX_CASELESS | G_REGEX_EXTENDED | G_REGEX_OPTIMIZE, G_REGEX_MATCH_NOTBOL | G_REGEX_MATCH_PARTIAL);
+-- 
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index a2de973e218..6dc3e0cc9cd 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -51,6 +51,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
            file://CVE-2026-58016-2.patch \
            file://CVE-2026-58010.patch \
            file://CVE-2026-58011.patch \
+           file://CVE-2026-58012.patch \
            "
 SRC_URI:append:class-native = " file://relocate-modules.patch \
                                 file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 28/31] glib-2.0: fix CVE-2026-58013
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (26 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 27/31] glib-2.0: fix CVE-2026-58012 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 29/31] glib-2.0: fix CVE-2026-58014 Yoann Congal
                   ` (2 subsequent siblings)
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

This patch applies the upstream 2.88.1 backport for
CVE-2026-58013. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://gitlab.gnome.org/GNOME/glib/-/commit/6a2583dec39bfe05553b16d9b7419d6c2a257244
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58013

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../glib-2.0/glib-2.0/CVE-2026-58013.patch    | 140 ++++++++++++++++++
 meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |   1 +
 2 files changed, 141 insertions(+)
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch

diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
new file mode 100644
index 00000000000..fa3db56bdbc
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
@@ -0,0 +1,140 @@
+From cb9d97e1b261d75eb8ea255e0a9f3e846d547af7 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 16:45:14 +0100
+Subject: [PATCH] giochannel: Fix memcmp() off the end of the buffer with long
+ terminators
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+If the line terminator is longer than a single byte, and the current
+line extends to the end of the buffer, and the buffer (which is a
+`GString`) is near a power of two in length (as that’s how `GString`s
+are allocated) it’s possible for the `memcmp()` which checks the
+terminator to read off the end of the string buffer.
+
+Fix that by checking the terminator length against the last character
+before calling `memcmp()`. Add a unit test.
+
+Spotted by linhlhq as #YWH-PGM9867-199. The fix is theirs (validated by
+me), and the unit test is adapted from their proof of concept.
+
+Fixes: #3925
+
+CVE: CVE-2026-58013
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/6a2583dec39bfe05553b16d9b7419d6c2a257244]
+
+Backport Changes:
+- Added the <stdint.h> include for the regression test because these target
+  branches do not otherwise expose uint8_t in glib/tests/io-channel.c.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit 6a2583dec39bfe05553b16d9b7419d6c2a257244)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/giochannel.c       |  3 ++-
+ glib/tests/io-channel.c | 61 +++++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 63 insertions(+), 1 deletion(-)
+
+diff --git a/glib/giochannel.c b/glib/giochannel.c
+index 7572c47a2..8d867d0fb 100644
+--- a/glib/giochannel.c
++++ b/glib/giochannel.c
+@@ -1833,7 +1833,8 @@ read_again:
+         {
+           if (channel->line_term)
+             {
+-              if (memcmp (channel->line_term, nextchar, line_term_len) == 0)
++              if ((size_t) (lastchar - nextchar) >= line_term_len &&
++                  memcmp (channel->line_term, nextchar, line_term_len) == 0)
+                 {
+                   line_length = nextchar - use_buf->str;
+                   got_term_len = line_term_len;
+diff --git a/glib/tests/io-channel.c b/glib/tests/io-channel.c
+index c5dd01d04..cf81a9f6b 100644
+--- a/glib/tests/io-channel.c
++++ b/glib/tests/io-channel.c
+@@ -29,6 +29,7 @@
+ 
+ #include <glib.h>
+ #include <glib/gstdio.h>
++#include <stdint.h>
+ 
+ static void
+ test_small_writes (void)
+@@ -216,6 +217,65 @@ test_read_line_embedded_nuls (void)
+   g_free (filename);
+ }
+ 
++static void
++test_read_line_long_terminator (void)
++{
++  uint8_t *test_data = NULL;
++  size_t test_data_len = 0;
++  int fd;
++  char *filename = NULL;
++  GIOChannel *channel = NULL;
++  GError *local_error = NULL;
++  char *line = NULL;
++  size_t line_length, terminator_pos;
++  const char *line_term;
++  int line_term_length;
++  GIOStatus status;
++
++  g_test_summary ("Test that reading a line when using a long terminator doesn’t over-read the buffer.");
++  g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/work_items/3925");
++
++  /* Write out a temporary file containing 2047 bytes. This is enough to make it
++   * near the length of the GString buffer when read back in. */
++  fd = g_file_open_tmp ("glib-test-io-channel-XXXXXX", &filename, &local_error);
++  g_assert_no_error (local_error);
++  g_close (g_steal_fd (&fd), NULL);
++
++  test_data_len = 2047;
++  test_data = g_malloc (test_data_len);
++  memset (test_data, 'M', test_data_len);
++  g_file_set_contents (filename, (const gchar *) test_data, test_data_len, &local_error);
++  g_assert_no_error (local_error);
++
++  /* Create the channel. */
++  channel = g_io_channel_new_file (filename, "r", &local_error);
++  g_assert_no_error (local_error);
++
++  /* Use a long line terminator so it could potentially over-read the end of the buffer. */
++  g_io_channel_set_line_term (channel, "DEADBEEF", 8);
++
++  line_term = g_io_channel_get_line_term (channel, &line_term_length);
++  g_assert_cmpstr (line_term, ==, "DEADBEEF");
++  g_assert_cmpint (line_term_length, ==, 8);
++
++  g_io_channel_set_encoding (channel, "UTF-8", &local_error);
++  g_assert_no_error (local_error);
++
++  status = g_io_channel_read_line (channel, &line, &line_length,
++                                   &terminator_pos, &local_error);
++  g_assert_no_error (local_error);
++  g_assert_cmpint (status, ==, G_IO_STATUS_NORMAL);
++  g_assert_cmpuint (line_length, ==, 2047);
++  g_assert_cmpuint (terminator_pos, ==, 2047);
++  g_assert_cmpmem (line, line_length, test_data, test_data_len);
++
++  g_free (line);
++  g_io_channel_unref (channel);
++  g_free (test_data);
++  g_unlink (filename);
++  g_free (filename);
++}
++
+ int
+ main (int   argc,
+       char *argv[])
+@@ -224,6 +283,7 @@ main (int   argc,
+ 
+   g_test_add_func ("/io-channel/read-write", test_read_write);
+   g_test_add_func ("/io-channel/read-line/embedded-nuls", test_read_line_embedded_nuls);
++  g_test_add_func ("/io-channel/read-line/long-terminator", test_read_line_long_terminator);
+ 
+   return g_test_run ();
+ }
+-- 
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 6dc3e0cc9cd..9516231cbad 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -52,6 +52,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
            file://CVE-2026-58010.patch \
            file://CVE-2026-58011.patch \
            file://CVE-2026-58012.patch \
+           file://CVE-2026-58013.patch \
            "
 SRC_URI:append:class-native = " file://relocate-modules.patch \
                                 file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 29/31] glib-2.0: fix CVE-2026-58014
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (27 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 28/31] glib-2.0: fix CVE-2026-58013 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 30/31] gzip: Fix CVE-2026-41991 Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 31/31] bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang Yoann Congal
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

This patch applies the upstream 2.88.1 backport for
CVE-2026-58014. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://gitlab.gnome.org/GNOME/glib/-/commit/94ecb5b44a1cae09f481dd5e693832f129948893
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58014

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../glib-2.0/glib-2.0/CVE-2026-58014.patch    | 106 ++++++++++++++++++
 meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |   1 +
 2 files changed, 107 insertions(+)
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch

diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
new file mode 100644
index 00000000000..4e5262b66de
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
@@ -0,0 +1,106 @@
+From ba0478c206bc04542df774343c6c85f77df49f6e Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Sat, 11 Apr 2026 14:42:57 +0100
+Subject: [PATCH] gkeyfile: Fix a one-byte heap under-read with
+ g_key_file_get_locale_string_list()
+
+If this method was called on a key file key which has an empty value,
+`len == 0` and this leads to a one-byte under-read off the start of the
+key file buffer.
+
+Spotted by linhlhq as #YWH-PGM9867-200. The suggested fix is theirs, and
+the unit test is adapted from their report. I added the fuzzing test.
+
+Fixes: #3930
+
+CVE: CVE-2026-58014
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/94ecb5b44a1cae09f481dd5e693832f129948893]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit 94ecb5b44a1cae09f481dd5e693832f129948893)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ fuzzing/fuzz_key.c   |  9 +++++++++
+ glib/gkeyfile.c      |  2 +-
+ glib/tests/keyfile.c | 23 +++++++++++++++++++++++
+ 3 files changed, 33 insertions(+), 1 deletion(-)
+
+diff --git a/fuzzing/fuzz_key.c b/fuzzing/fuzz_key.c
+index 77cb684..7d00443 100644
+--- a/fuzzing/fuzz_key.c
++++ b/fuzzing/fuzz_key.c
+@@ -26,11 +26,20 @@ test_parse (const gchar   *data,
+             GKeyFileFlags  flags)
+ {
+   GKeyFile *key = NULL;
++  char *comment = NULL;
++  char **list = NULL;
+ 
+   key = g_key_file_new ();
+   g_key_file_load_from_data (key, (const gchar*) data, size, G_KEY_FILE_NONE,
+                              NULL);
+ 
++  /* Also try some additional parsing and see if it crashes */
++  comment = g_key_file_get_comment (key, "group", "key", NULL);
++  g_free (comment);
++
++  list = g_key_file_get_locale_string_list (key, "group", "key", "de", NULL, NULL);
++  g_strfreev (list);
++
+   g_key_file_free (key);
+ }
+ 
+diff --git a/glib/gkeyfile.c b/glib/gkeyfile.c
+index d08a485..54d77a5 100644
+--- a/glib/gkeyfile.c
++++ b/glib/gkeyfile.c
+@@ -2421,7 +2421,7 @@ g_key_file_get_locale_string_list (GKeyFile     *key_file,
+     }
+ 
+   len = strlen (value);
+-  if (value[len - 1] == key_file->list_separator)
++  if (len > 0 && value[len - 1] == key_file->list_separator)
+     value[len - 1] = '\0';
+ 
+   list_separator[0] = key_file->list_separator;
+diff --git a/glib/tests/keyfile.c b/glib/tests/keyfile.c
+index bc125c1..289bd2b 100644
+--- a/glib/tests/keyfile.c
++++ b/glib/tests/keyfile.c
+@@ -850,6 +850,28 @@ test_locale_string_multiple_loads (void)
+   g_free (old_locale);
+ }
+ 
++static void
++test_locale_string_empty (void)
++{
++  GKeyFile *keyfile = NULL;
++  GError *local_error = NULL;
++  const char *data =
++    "[valid]\n"
++    "key1=\n";
++
++  g_test_summary ("Check that loading an empty translatable string works");
++  g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3930");
++
++  keyfile = g_key_file_new ();
++
++  g_key_file_load_from_data (keyfile, data, -1, G_KEY_FILE_NONE, &local_error);
++  g_assert_no_error (local_error);
++
++  check_locale_string_list_value (keyfile, "valid", "key1", NULL, NULL);
++
++  g_key_file_free (keyfile);
++}
++
+ static void
+ test_lists (void)
+ {
+@@ -1939,6 +1961,7 @@ main (int argc, char *argv[])
+   g_test_add_func ("/keyfile/number", test_number);
+   g_test_add_func ("/keyfile/locale-string", test_locale_string);
+   g_test_add_func ("/keyfile/locale-string/multiple-loads", test_locale_string_multiple_loads);
++  g_test_add_func ("/keyfile/locale-string/empty", test_locale_string_empty);
+   g_test_add_func ("/keyfile/lists", test_lists);
+   g_test_add_func ("/keyfile/lists-set-get", test_lists_set_get);
+   g_test_add_func ("/keyfile/group-remove", test_group_remove);
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 9516231cbad..e15aa1fe206 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -53,6 +53,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
            file://CVE-2026-58011.patch \
            file://CVE-2026-58012.patch \
            file://CVE-2026-58013.patch \
+           file://CVE-2026-58014.patch \
            "
 SRC_URI:append:class-native = " file://relocate-modules.patch \
                                 file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 30/31] gzip: Fix CVE-2026-41991
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (28 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 29/31] glib-2.0: fix CVE-2026-58014 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  2026-07-26  8:29 ` [OE-core][scarthgap 31/31] bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang Yoann Congal
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Darsh Kelaiya <dkelaiya@cisco.com>

This patch applies the upstream fix for CVE-2026-41991 as referenced
in [2], using the upstream commit identified in [1].

[1] https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-41991

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../gzip/gzip-1.13/CVE-2026-41991.patch       | 75 +++++++++++++++++++
 meta/recipes-extended/gzip/gzip_1.13.bb       |  1 +
 2 files changed, 76 insertions(+)
 create mode 100644 meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch

diff --git a/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch b/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch
new file mode 100644
index 00000000000..9728b38658d
--- /dev/null
+++ b/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch
@@ -0,0 +1,75 @@
+From 0af3a96047fe02690473d4e106c39552e0c1285e Mon Sep 17 00:00:00 2001
+From: Paul Eggert <eggert@cs.ucla.edu>
+Date: Thu, 16 Apr 2026 12:11:44 -0700
+Subject: [PATCH] gzexe: use -C if lacking mktemp
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+(Problem reported by Michał Majchrowicz.)
+* gzexe.in: If mktemp is needed but not installed,
+use ‘set -C’ to avoid a race when creating a temporary file.
+* zdiff.in: Use the same pattern here, even though the old
+code was probably OK anyway.
+
+CVE: CVE-2026-41991
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269]
+
+(cherry picked from commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ NEWS     | 5 +++++
+ gzexe.in | 1 +
+ zdiff.in | 7 +++----
+ 3 files changed, 9 insertions(+), 4 deletions(-)
+
+diff --git a/NEWS b/NEWS
+index 6a20892..c643b2f 100644
+--- a/NEWS
++++ b/NEWS
+@@ -1,5 +1,10 @@
+ GNU gzip NEWS                                    -*- outline -*-
+ 
++  On old-fashioned or limited platforms lacking mktemp, gzexe and
++  zdiff no longer have a race when creating a temporary file.
++  [bug present since the beginning]
++
++
+ * Noteworthy changes in release 1.13 (2023-08-19) [stable]
+ 
+ ** Changes in behavior
+diff --git a/gzexe.in b/gzexe.in
+index 5e3d4c2..f31b9c8 100644
+--- a/gzexe.in
++++ b/gzexe.in
+@@ -128,6 +128,7 @@ for i do
+     tmp=`mktemp "${dir}gzexeXXXXXXXXX"`
+   else
+     tmp=${dir}gzexe$$
++    (umask 77; set -C; > "$tmp")
+   fi && { cp -p "$file" "$tmp" 2>/dev/null || cp "$file" "$tmp"; } || {
+     res=$?
+     printf >&2 '%s\n' "$0: cannot copy $file"
+diff --git a/zdiff.in b/zdiff.in
+index e35e6fe..bbcc75b 100644
+--- a/zdiff.in
++++ b/zdiff.in
+@@ -157,12 +157,11 @@ case $file2 in
+                           *) TMPDIR=/tmp/;;
+                         esac
+                         if type mktemp >/dev/null 2>&1; then
+-                          tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"` ||
+-                            exit 2
++                          tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"`
+                         else
+-                          set -C
+                           tmp=${TMPDIR}zdiff$$
+-                        fi
++                          (umask 77; set -C; > "$tmp")
++                        fi &&
+                         'gzip' -cdfq -- "$file2" > "$tmp" || exit 2
+                         gzip_status=$(
+                           exec 4>&1
+-- 
+2.44.4
+
diff --git a/meta/recipes-extended/gzip/gzip_1.13.bb b/meta/recipes-extended/gzip/gzip_1.13.bb
index 208220867a6..4ab3b1d523c 100644
--- a/meta/recipes-extended/gzip/gzip_1.13.bb
+++ b/meta/recipes-extended/gzip/gzip_1.13.bb
@@ -7,6 +7,7 @@ LICENSE = "GPL-3.0-or-later"
 SRC_URI = "${GNU_MIRROR}/gzip/${BP}.tar.gz \
            file://run-ptest \
            file://CVE-2026-41992.patch \
+           file://CVE-2026-41991.patch \
            "
 SRC_URI:append:class-target = " file://wrong-path-fix.patch"
 


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [OE-core][scarthgap 31/31] bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang
  2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
                   ` (29 preceding siblings ...)
  2026-07-26  8:29 ` [OE-core][scarthgap 30/31] gzip: Fix CVE-2026-41991 Yoann Congal
@ 2026-07-26  8:29 ` Yoann Congal
  30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26  8:29 UTC (permalink / raw)
  To: openembedded-core

From: Hongxu Jia <hongxu.jia@windriver.com>

According to [1]

As of the current version 1.0.8, bzip2 --version will print version
info but it will also continue compressing stdin:

  $ ./bzip2 --version
  bzip2, a block-sorting file compressor.  Version 1.0.8, 13-Jul-2019.

     Copyright (C) 1996-2019 by Julian Seward.

     This program is free software; [...]

  bzip2: I won't write compressed data to a terminal.
  bzip2: For help, type: `bzip2 --help'.

This is a long-standing bug, not new to 1.0.8 -- the same code
(license() followed by break, with no exit) exists in bzip2 1.0.6 and
earlier. The upstream bzip2 master branch on GitLab already includes
this fix.

Debian (and its downstreams like Ubuntu) will patch this out [2],
making the < /dev/null unnecessary, port a part of debian patch
to fix the issue

[1] https://stackoverflow.com/questions/59757176/why-using-dev-null-with-a-program-like-bzip2
[2] https://sources.debian.org/src/bzip2/1.0.8-6/debian/patches/20-legacy.patch/

Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit ae4fe4263ba9d372f9b9e80df4ec4697b51c1f9b)
[Jaipaul: backport to scarthgap -- added commit message context that this is a
long-standing bug (not new to 1.0.8), updated Upstream-Status in patch
to actual mailing list URL in the patch file, this patch is already present on master,
wrynose and walnascar branches using the same bzip2 1.0.8]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 ...-fix-bzip2-version-tmp-aaa-will-hang.patch | 65 +++++++++++++++++++
 meta/recipes-extended/bzip2/bzip2_1.0.8.bb    |  1 +
 2 files changed, 66 insertions(+)
 create mode 100644 meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch

diff --git a/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch b/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch
new file mode 100644
index 00000000000..2d02328d116
--- /dev/null
+++ b/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch
@@ -0,0 +1,65 @@
+From a9dd6acbaca836fc4e943e69a31b2e7acda32045 Mon Sep 17 00:00:00 2001
+From: Hongxu Jia <hongxu.jia@windriver.com>
+Date: Wed, 13 Nov 2024 19:49:23 +0800
+Subject: [PATCH] fix 'bzip2 --version > /tmp/aaa 2>&1' hang
+
+According to [1]
+
+As of the current version 1.0.8, bzip2 --version will print version
+info but it will also continue compressing stdin:
+
+  $ ./bzip2 --version
+  bzip2, a block-sorting file compressor.  Version 1.0.8, 13-Jul-2019.
+  
+     Copyright (C) 1996-2019 by Julian Seward.
+  
+     This program is free software; [...]
+  
+  bzip2: I won't write compressed data to a terminal.
+  bzip2: For help, type: `bzip2 --help'.
+
+Debian (and its downstreams like Ubuntu) will patch this out [2],
+making the < /dev/null unnecessary:
+
+[1] https://stackoverflow.com/questions/59757176/why-using-dev-null-with-a-program-like-bzip2
+[2] https://sources.debian.org/src/bzip2/1.0.8-6/debian/patches/20-legacy.patch/
+
+Upstream-Status: Submitted [https://sourceware.org/pipermail/bzip2-devel/2024q4/000234.html]
+Note: updated Upstream-Status URL to point to the actual mailing list
+archive entry.
+
+Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ bzip2.c | 8 +++++---
+ 1 file changed, 5 insertions(+), 3 deletions(-)
+
+diff --git a/bzip2.c b/bzip2.c
+index d95d280..6ec9871 100644
+--- a/bzip2.c
++++ b/bzip2.c
+@@ -1890,7 +1890,9 @@ IntNative main ( IntNative argc, Char *argv[] )
+                case '8': blockSize100k    = 8; break;
+                case '9': blockSize100k    = 9; break;
+                case 'V':
+-               case 'L': license();            break;
++               case 'L': license();
++                         exit ( 0 );
++                         break;
+                case 'v': verbosity++; break;
+                case 'h': usage ( progName );
+                          exit ( 0 );
+@@ -1916,8 +1918,8 @@ IntNative main ( IntNative argc, Char *argv[] )
+       if (ISFLAG("--keep"))              keepInputFiles   = True;    else
+       if (ISFLAG("--small"))             smallMode        = True;    else
+       if (ISFLAG("--quiet"))             noisy            = False;   else
+-      if (ISFLAG("--version"))           license();                  else
+-      if (ISFLAG("--license"))           license();                  else
++      if (ISFLAG("--version"))           { license(); exit ( 0 ); }  else
++      if (ISFLAG("--license"))           { license(); exit ( 0 ); }  else
+       if (ISFLAG("--exponential"))       workFactor = 1;             else 
+       if (ISFLAG("--repetitive-best"))   redundant(aa->name);        else
+       if (ISFLAG("--repetitive-fast"))   redundant(aa->name);        else
+-- 
+2.34.1
+
diff --git a/meta/recipes-extended/bzip2/bzip2_1.0.8.bb b/meta/recipes-extended/bzip2/bzip2_1.0.8.bb
index b661bc95465..6c02dc3ed06 100644
--- a/meta/recipes-extended/bzip2/bzip2_1.0.8.bb
+++ b/meta/recipes-extended/bzip2/bzip2_1.0.8.bb
@@ -27,6 +27,7 @@ SRC_URI = "https://sourceware.org/pub/${BPN}/${BPN}-${PV}.tar.gz \
            file://Makefile.am;subdir=${BP} \
            file://run-ptest \
            file://CVE-2026-42250.patch;subdir=${BP} \
+           file://0001-fix-bzip2-version-tmp-aaa-will-hang.patch;subdir=${BP} \
            "
 SRC_URI[md5sum] = "67e051268d0c475ea773822f7500d0e5"
 SRC_URI[sha256sum] = "ab5a03176ee106d3f0fa90e381da478ddae405918153cca248e682cd0c4a2269"


^ permalink raw reply related	[flat|nested] 32+ messages in thread

end of thread, other threads:[~2026-07-26  8:30 UTC | newest]

Thread overview: 32+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-26  8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 02/31] linux-yocto/6.6: update to v6.6.143 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 03/31] linux-yocto/6.6: update to v6.6.144 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 04/31] linux-yocto/6.6: update CVE exclusions (6.6.144) Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 05/31] libxml2: Fix CVE-2026-11979 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 06/31] openssh: Fix CVE-2026-59999 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 07/31] openssh: Fix CVE-2026-59997 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 08/31] openssh: Fix CVE-2026-59996 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 09/31] openssh: Fix CVE-2026-59995 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 10/31] openssh: Fix CVE-2026-60001 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 11/31] openssh: Fix CVE-2026-60002 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 12/31] openssh: Fix CVE-2026-60000 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 13/31] cups: fix CVE-2026-27447 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 14/31] cups: fix CVE-2026-41079 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 15/31] cups: fix CVE-2026-34978 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 16/31] cups: fix CVE-2026-34980 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 17/31] cups: fix CVE-2026-34979 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 18/31] cups: fix CVE-2026-34990 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 19/31] cups: fix CVE-2026-39314 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 20/31] cups: fix CVE-2026-39316 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 21/31] libxpm: fix CVE-2026-4367 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 22/31] gnutls: set status for CVE-2026-3832 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 23/31] gnutls: fix CVE-2026-42009 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 24/31] libpng: Fix CVE-2026-34757 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 25/31] glib-2.0: fix CVE-2026-58010 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 26/31] glib-2.0: fix CVE-2026-58011 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 27/31] glib-2.0: fix CVE-2026-58012 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 28/31] glib-2.0: fix CVE-2026-58013 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 29/31] glib-2.0: fix CVE-2026-58014 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 30/31] gzip: Fix CVE-2026-41991 Yoann Congal
2026-07-26  8:29 ` [OE-core][scarthgap 31/31] bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang Yoann Congal

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.