From: Yoann Congal <yoann.congal@smile.fr>
To: openembedded-core@lists.openembedded.org
Subject: [OE-core][wrynose 00/36] Patch review
Date: Tue, 28 Jul 2026 00:55:14 +0200 [thread overview]
Message-ID: <cover.1785190123.git.yoann.congal@smile.fr> (raw)
Please review this set of changes for wrynose and have comments back by
end of day Wednesday, July 29.
Note: the Rsync patches of this series are bigger than usual CVE
patches (and also AI generated) so they might need extra care.
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/4303
The following changes since commit f66b182e2ff431b624dfc3a506d25dc8f1fc6db2:
gzip: Fix CVE-2026-41991 (2026-07-27 09:47:02 +0100)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/wrynose-nut
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/wrynose-nut
for you to fetch changes up to d174aa123d5a3e7dab771a060b2d173192e11535:
vim: Security Fix for CVE-2026-57452 (2026-07-27 12:48:07 +0200)
----------------------------------------------------------------
Adarsh Jagadish Kamini (1):
gnutls: fix CVE-2026-3833
AshishKumar Mishra (1):
package.bbclass: hardcode emit_pkgdata to run last
Ashishkumar Parmar (6):
rsync: Fix CVE-2026-29518
rsync: Fix CVE-2026-43619
rsync: Fix CVE-2026-43618
rsync: Fix CVE-2026-43620
rsync: Fix CVE-2026-43617
rsync: Fix CVE-2026-45232
Bruce Ashfield (4):
linux-yocto/6.18: update to v6.18.36
linux-yocto/6.18: update to v6.18.38
linux-yocto/6.18: update to v6.18.39
linux-yocto/6.18: drm/virtio: fix deadlock in display_info_cb by
removing hotplug from dequeue worker
Daniel Turull (2):
systemd-systemctl-native: disable libpam meson option
xmlto: correct srcrev to point to released version
Darsh Kelaiya (5):
gawk: Fix CVE-2026-40467
gawk: Fix CVE-2026-40468
gawk: Fix CVE-2026-40469
gawk: Fix CVE-2026-40553
python3-setuptools: Fix CVE-2026-59890
Deepak Rathore (2):
curl: fix CVE-2026-7168
sqlite3: fix CVE-2026-11822 and CVE-2026-11824
Devansh Patel (1):
openssh: set status for CVE-2026-59998
João Marcos Costa (1):
curl: add annotation for CVE-2026-10536
Leonid Iziumtsev (2):
libgcrypt: fix CVE-2026-41989
libgcrypt: fix CVE-2026-41990
Peter Marko (1):
libpng: set status for CVE-2026-40930
Siddharth Doshi (6):
vim: Security Fix for CVE-2026-42307
vim: Security Fix for CVE-2026-43961
vim: Security Fix for CVE-2026-47162
vim: Security Fix for CVE-2026-47167
vim: Security Fix for CVE-2026-55892
vim: Security Fix for CVE-2026-57452
Siva Balasubramanian (1):
util-linux: upgrade 2.41.3 -> 2.41.5
mark.yang (3):
python3-cryptography: set CVE_PRODUCT
python3-ply: set CVE_PRODUCT
python3-pyasn1: set CVE_PRODUCT
meta/classes-global/package.bbclass | 7 +-
.../openssh/openssh_10.3p1.bb | 1 +
.../systemd/systemd-systemctl-native_259.5.bb | 1 +
...2.41.3.bb => util-linux-libuuid_2.41.5.bb} | 0
meta/recipes-core/util-linux/util-linux.inc | 4 +-
...DEV_FL_NOFOLLOW-to-prevent-symlink-a.patch | 114 --
.../util-linux/CVE-2026-13595.patch | 148 --
...l-linux_2.41.3.bb => util-linux_2.41.5.bb} | 0
.../python/python3-cryptography.bb | 2 +
.../python/python3-ply_3.11.bb | 2 +
.../python/python3-pyasn1_0.6.2.bb | 2 +
.../python3-setuptools/CVE-2026-59890.patch | 194 ++
.../python/python3-setuptools_82.0.1.bb | 3 +-
.../rsync/files/CVE-2026-29518_p1.patch | 392 ++++
.../rsync/files/CVE-2026-29518_p2.patch | 98 +
.../rsync/files/CVE-2026-29518_p3.patch | 328 +++
.../rsync/files/CVE-2026-29518_p4.patch | 71 +
.../rsync/files/CVE-2026-43617.patch | 201 ++
.../rsync/files/CVE-2026-43618.patch | 248 +++
.../rsync/files/CVE-2026-43619_p1.patch | 471 +++++
.../rsync/files/CVE-2026-43619_p2.patch | 205 ++
.../rsync/files/CVE-2026-43619_p3.patch | 1783 +++++++++++++++++
.../rsync/files/CVE-2026-43619_p4.patch | 568 ++++++
.../rsync/files/CVE-2026-43619_p5.patch | 69 +
.../rsync/files/CVE-2026-43619_p6.patch | 258 +++
.../rsync/files/CVE-2026-43620.patch | 122 ++
.../rsync/files/CVE-2026-45232.patch | 240 +++
meta/recipes-devtools/rsync/rsync_3.4.1.bb | 14 +
meta/recipes-devtools/xmlto/xmlto_0.0.29.bb | 4 +-
.../gawk/gawk/CVE-2026-40467.patch | 62 +
.../gawk/gawk/CVE-2026-40468.patch | 61 +
.../gawk/gawk/CVE-2026-40469.patch | 90 +
.../gawk/gawk/CVE-2026-40553_p1.patch | 50 +
.../gawk/gawk/CVE-2026-40553_p2.patch | 44 +
meta/recipes-extended/gawk/gawk_5.4.0.bb | 5 +
.../linux/linux-yocto-rt_6.18.bb | 6 +-
.../linux/linux-yocto-tiny_6.18.bb | 6 +-
meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +-
.../libpng/libpng_1.6.56.bb | 2 +
.../curl/curl/CVE-2026-7168.patch | 376 ++++
meta/recipes-support/curl/curl_8.19.0.bb | 2 +
.../gnutls/gnutls/CVE-2026-3833.patch | 90 +
meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 +
.../libgcrypt/files/CVE-2026-41989.patch | 42 +
.../libgcrypt/files/CVE-2026-41990.patch | 316 +++
.../libgcrypt/libgcrypt_1.12.1.bb | 2 +
.../CVE-2026-11822_CVE-2026-11824.patch | 41 +
meta/recipes-support/sqlite/sqlite3_3.51.3.bb | 5 +-
.../vim/files/CVE-2026-42307.patch | 177 ++
.../vim/files/CVE-2026-43961.patch | 104 +
.../vim/files/CVE-2026-47162.patch | 83 +
.../vim/files/CVE-2026-47167.patch | 102 +
.../vim/files/CVE-2026-55892.patch | 95 +
.../vim/files/CVE-2026-57452.patch | 90 +
meta/recipes-support/vim/vim.inc | 6 +
55 files changed, 7143 insertions(+), 289 deletions(-)
rename meta/recipes-core/util-linux/{util-linux-libuuid_2.41.3.bb => util-linux-libuuid_2.41.5.bb} (100%)
delete mode 100644 meta/recipes-core/util-linux/util-linux/0001-loopdev-add-LOOPDEV_FL_NOFOLLOW-to-prevent-symlink-a.patch
delete mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-13595.patch
rename meta/recipes-core/util-linux/{util-linux_2.41.3.bb => util-linux_2.41.5.bb} (100%)
create mode 100644 meta/recipes-devtools/python/python3-setuptools/CVE-2026-59890.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-29518_p1.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-29518_p2.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-29518_p3.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-29518_p4.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-43617.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-43618.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-43619_p1.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-43619_p2.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-43619_p3.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-43619_p4.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-43619_p5.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-43619_p6.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-43620.patch
create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-45232.patch
create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40467.patch
create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40468.patch
create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40469.patch
create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40553_p1.patch
create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40553_p2.patch
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-7168.patch
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-3833.patch
create mode 100644 meta/recipes-support/libgcrypt/files/CVE-2026-41989.patch
create mode 100644 meta/recipes-support/libgcrypt/files/CVE-2026-41990.patch
create mode 100644 meta/recipes-support/sqlite/sqlite3/CVE-2026-11822_CVE-2026-11824.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-42307.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-43961.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-47162.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-47167.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch
next reply other threads:[~2026-07-27 22:56 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 22:55 Yoann Congal [this message]
2026-07-27 22:55 ` [OE-core][wrynose 01/36] curl: fix CVE-2026-7168 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 02/36] gawk: Fix CVE-2026-40467 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 03/36] gawk: Fix CVE-2026-40468 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 04/36] gawk: Fix CVE-2026-40469 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 05/36] gawk: Fix CVE-2026-40553 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 06/36] rsync: Fix CVE-2026-29518 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 07/36] rsync: Fix CVE-2026-43619 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 08/36] rsync: Fix CVE-2026-43618 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 09/36] rsync: Fix CVE-2026-43620 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 10/36] rsync: Fix CVE-2026-43617 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 11/36] rsync: Fix CVE-2026-45232 Yoann Congal
2026-07-28 13:25 ` Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 12/36] gnutls: fix CVE-2026-3833 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 13/36] libpng: set status for CVE-2026-40930 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 14/36] python3-cryptography: set CVE_PRODUCT Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 15/36] python3-ply: " Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 16/36] python3-pyasn1: " Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 17/36] python3-setuptools: Fix CVE-2026-59890 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 18/36] openssh: set status for CVE-2026-59998 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 19/36] libgcrypt: fix CVE-2026-41989 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 20/36] libgcrypt: fix CVE-2026-41990 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 21/36] sqlite3: fix CVE-2026-11822 and CVE-2026-11824 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 22/36] curl: add annotation for CVE-2026-10536 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 23/36] package.bbclass: hardcode emit_pkgdata to run last Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 24/36] systemd-systemctl-native: disable libpam meson option Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 25/36] util-linux: upgrade 2.41.3 -> 2.41.5 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 26/36] linux-yocto/6.18: update to v6.18.36 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 27/36] linux-yocto/6.18: update to v6.18.38 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 28/36] linux-yocto/6.18: update to v6.18.39 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 29/36] linux-yocto/6.18: drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 30/36] xmlto: correct srcrev to point to released version Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 31/36] vim: Security Fix for CVE-2026-42307 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 32/36] vim: Security Fix for CVE-2026-43961 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 33/36] vim: Security Fix for CVE-2026-47162 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 34/36] vim: Security Fix for CVE-2026-47167 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 35/36] vim: Security Fix for CVE-2026-55892 Yoann Congal
2026-07-27 22:55 ` [OE-core][wrynose 36/36] vim: Security Fix for CVE-2026-57452 Yoann Congal
-- strict thread matches above, loose matches on Subject: below --
2026-06-20 12:59 [OE-core][wrynose 00/36] Patch review Yoann Congal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cover.1785190123.git.yoann.congal@smile.fr \
--to=yoann.congal@smile.fr \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.