From: Yoann Congal <yoann.congal@smile.fr>
To: openembedded-core@lists.openembedded.org
Cc: Paul Barker <paul@pbarker.dev>
Subject: [OE-core][wrynose 00/30] Pull request (cover letter only)
Date: Thu, 30 Jul 2026 10:33:32 +0200 [thread overview]
Message-ID: <cover.1785400140.git.yoann.congal@smile.fr> (raw)
Warning: this contains a linux-yocto upgrade that must be merged with the
corresponding yocto-bsps upgrade in meta-yocto.
Those are the patches from the last patch review:
https://lore.kernel.org/openembedded-core/cover.1785190123.git.yoann.congal@smile.fr/T/#u
From this series, the rsync patches where removed:
* rsync: Fix CVE-2026-29518
* rsync: Fix CVE-2026-43619
* rsync: Fix CVE-2026-43618
* rsync: Fix CVE-2026-43620
* rsync: Fix CVE-2026-43617
* rsync: Fix CVE-2026-45232
See: https://lore.kernel.org/all/DKAZFDFRUHBF.2SVVF2X00US95@smile.fr/
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/4313
The following changes since commit f66b182e2ff431b624dfc3a506d25dc8f1fc6db2:
gzip: Fix CVE-2026-41991 (2026-07-27 09:47:02 +0100)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/wrynose-next
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/wrynose-next
for you to fetch changes up to 243aa188889c765564c75247b7314e3f6168520a:
vim: Security Fix for CVE-2026-57452 (2026-07-28 15:32:17 +0200)
----------------------------------------------------------------
Adarsh Jagadish Kamini (1):
gnutls: fix CVE-2026-3833
AshishKumar Mishra (1):
package.bbclass: hardcode emit_pkgdata to run last
Bruce Ashfield (4):
linux-yocto/6.18: update to v6.18.36
linux-yocto/6.18: update to v6.18.38
linux-yocto/6.18: update to v6.18.39
linux-yocto/6.18: drm/virtio: fix deadlock in display_info_cb by
removing hotplug from dequeue worker
Daniel Turull (2):
systemd-systemctl-native: disable libpam meson option
xmlto: correct srcrev to point to released version
Darsh Kelaiya (5):
gawk: Fix CVE-2026-40467
gawk: Fix CVE-2026-40468
gawk: Fix CVE-2026-40469
gawk: Fix CVE-2026-40553
python3-setuptools: Fix CVE-2026-59890
Deepak Rathore (2):
curl: fix CVE-2026-7168
sqlite3: fix CVE-2026-11822 and CVE-2026-11824
Devansh Patel (1):
openssh: set status for CVE-2026-59998
João Marcos Costa (1):
curl: add annotation for CVE-2026-10536
Leonid Iziumtsev (2):
libgcrypt: fix CVE-2026-41989
libgcrypt: fix CVE-2026-41990
Peter Marko (1):
libpng: set status for CVE-2026-40930
Siddharth Doshi (6):
vim: Security Fix for CVE-2026-42307
vim: Security Fix for CVE-2026-43961
vim: Security Fix for CVE-2026-47162
vim: Security Fix for CVE-2026-47167
vim: Security Fix for CVE-2026-55892
vim: Security Fix for CVE-2026-57452
Siva Balasubramanian (1):
util-linux: upgrade 2.41.3 -> 2.41.5
mark.yang (3):
python3-cryptography: set CVE_PRODUCT
python3-ply: set CVE_PRODUCT
python3-pyasn1: set CVE_PRODUCT
meta/classes-global/package.bbclass | 7 +-
.../openssh/openssh_10.3p1.bb | 1 +
.../systemd/systemd-systemctl-native_259.5.bb | 1 +
...2.41.3.bb => util-linux-libuuid_2.41.5.bb} | 0
meta/recipes-core/util-linux/util-linux.inc | 4 +-
...DEV_FL_NOFOLLOW-to-prevent-symlink-a.patch | 114 ------
.../util-linux/CVE-2026-13595.patch | 148 -------
...l-linux_2.41.3.bb => util-linux_2.41.5.bb} | 0
.../python/python3-cryptography.bb | 2 +
.../python/python3-ply_3.11.bb | 2 +
.../python/python3-pyasn1_0.6.2.bb | 2 +
.../python3-setuptools/CVE-2026-59890.patch | 194 +++++++++
.../python/python3-setuptools_82.0.1.bb | 3 +-
meta/recipes-devtools/xmlto/xmlto_0.0.29.bb | 4 +-
.../gawk/gawk/CVE-2026-40467.patch | 62 +++
.../gawk/gawk/CVE-2026-40468.patch | 61 +++
.../gawk/gawk/CVE-2026-40469.patch | 90 +++++
.../gawk/gawk/CVE-2026-40553_p1.patch | 50 +++
.../gawk/gawk/CVE-2026-40553_p2.patch | 44 ++
meta/recipes-extended/gawk/gawk_5.4.0.bb | 5 +
.../linux/linux-yocto-rt_6.18.bb | 6 +-
.../linux/linux-yocto-tiny_6.18.bb | 6 +-
meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +-
.../libpng/libpng_1.6.56.bb | 2 +
.../curl/curl/CVE-2026-7168.patch | 376 ++++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 2 +
.../gnutls/gnutls/CVE-2026-3833.patch | 90 +++++
meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 +
.../libgcrypt/files/CVE-2026-41989.patch | 42 ++
.../libgcrypt/files/CVE-2026-41990.patch | 316 +++++++++++++++
.../libgcrypt/libgcrypt_1.12.1.bb | 2 +
.../CVE-2026-11822_CVE-2026-11824.patch | 41 ++
meta/recipes-support/sqlite/sqlite3_3.51.3.bb | 5 +-
.../vim/files/CVE-2026-42307.patch | 177 +++++++++
.../vim/files/CVE-2026-43961.patch | 104 +++++
.../vim/files/CVE-2026-47162.patch | 83 ++++
.../vim/files/CVE-2026-47167.patch | 102 +++++
.../vim/files/CVE-2026-55892.patch | 95 +++++
.../vim/files/CVE-2026-57452.patch | 90 +++++
meta/recipes-support/vim/vim.inc | 6 +
40 files changed, 2075 insertions(+), 289 deletions(-)
rename meta/recipes-core/util-linux/{util-linux-libuuid_2.41.3.bb => util-linux-libuuid_2.41.5.bb} (100%)
delete mode 100644 meta/recipes-core/util-linux/util-linux/0001-loopdev-add-LOOPDEV_FL_NOFOLLOW-to-prevent-symlink-a.patch
delete mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-13595.patch
rename meta/recipes-core/util-linux/{util-linux_2.41.3.bb => util-linux_2.41.5.bb} (100%)
create mode 100644 meta/recipes-devtools/python/python3-setuptools/CVE-2026-59890.patch
create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40467.patch
create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40468.patch
create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40469.patch
create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40553_p1.patch
create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40553_p2.patch
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-7168.patch
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-3833.patch
create mode 100644 meta/recipes-support/libgcrypt/files/CVE-2026-41989.patch
create mode 100644 meta/recipes-support/libgcrypt/files/CVE-2026-41990.patch
create mode 100644 meta/recipes-support/sqlite/sqlite3/CVE-2026-11822_CVE-2026-11824.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-42307.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-43961.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-47162.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-47167.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch
reply other threads:[~2026-07-30 8:33 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cover.1785400140.git.yoann.congal@smile.fr \
--to=yoann.congal@smile.fr \
--cc=openembedded-core@lists.openembedded.org \
--cc=paul@pbarker.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.