All of lore.kernel.org
 help / color / mirror / Atom feed
* [OE-core][scarthgap 00/11] Patch review
@ 2024-09-16  2:19 Steve Sakoman
  0 siblings, 0 replies; 25+ messages in thread
From: Steve Sakoman @ 2024-09-16  2:19 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Tuesday, September 17

Passed a-full on autobuilder:

https://autobuilder.yoctoproject.org/typhoon/#/builders/83/builds/7330

The following changes since commit 7e11701698a9f38a5e3e0499c0c2edd98d32a85d:

  mc: fix source URL (2024-09-03 06:59:38 -0700)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

Michael Halstead (1):
  yocto-uninative: Update to 4.6 for glibc 2.40

Niko Mauno (7):
  iw: Fix LICENSE
  dejagnu: Fix LICENSE
  unzip: Fix LICENSE
  zip: Fix LICENSE
  tiff: Fix LICENSE
  gcr: Fix LICENSE
  python3-maturin: Fix cross compilation issue for armv7l, mips64, ppc

Richard Purdie (2):
  expat: 2.6.2 -> 2.6.3
  ruby: Make docs generation deterministic

Siddharth Doshi (1):
  vim: Upgrade 9.1.0682 -> 9.1.0698

 meta/conf/distro/include/yocto-uninative.inc  |  10 +-
 meta/recipes-connectivity/iw/iw_6.7.bb        |   2 +-
 .../expat/{expat_2.6.2.bb => expat_2.6.3.bb}  |   2 +-
 .../recipes-devtools/dejagnu/dejagnu_1.6.3.bb |   2 +-
 ...n-architecture-name-resolvation-code.patch | 107 ++++++++++++++++++
 ...ation-issue-with-linux-armv7l-archit.patch |  76 +++++++++++++
 ...n-ABI-name-resolvation-code-as-helpe.patch |  98 ++++++++++++++++
 ...ation-issue-with-linux-ppc-architect.patch |  68 +++++++++++
 ...ation-issue-with-linux-mips64-archit.patch |  82 ++++++++++++++
 .../python/python3-maturin_1.4.0.bb           |   7 ++
 meta/recipes-devtools/ruby/ruby_3.2.2.bb      |   1 +
 meta/recipes-extended/unzip/unzip_6.0.bb      |   2 +-
 meta/recipes-extended/zip/zip_3.0.bb          |   2 +-
 meta/recipes-gnome/gcr/gcr_4.2.1.bb           |   2 +-
 meta/recipes-multimedia/libtiff/tiff_4.6.0.bb |   2 +-
 meta/recipes-support/vim/vim.inc              |   4 +-
 16 files changed, 453 insertions(+), 14 deletions(-)
 rename meta/recipes-core/expat/{expat_2.6.2.bb => expat_2.6.3.bb} (92%)
 create mode 100644 meta/recipes-devtools/python/python3-maturin/0001-Extract-extension-architecture-name-resolvation-code.patch
 create mode 100644 meta/recipes-devtools/python/python3-maturin/0002-Fix-cross-compilation-issue-with-linux-armv7l-archit.patch
 create mode 100644 meta/recipes-devtools/python/python3-maturin/0003-Extract-extension-ABI-name-resolvation-code-as-helpe.patch
 create mode 100644 meta/recipes-devtools/python/python3-maturin/0004-Fix-cross-compilation-issue-with-linux-ppc-architect.patch
 create mode 100644 meta/recipes-devtools/python/python3-maturin/0005-Fix-cross-compilation-issue-with-linux-mips64-archit.patch

-- 
2.34.1



^ permalink raw reply	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 00/11] Patch review
@ 2024-10-25 18:29 Steve Sakoman
  0 siblings, 0 replies; 25+ messages in thread
From: Steve Sakoman @ 2024-10-25 18:29 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Tuesday, October 29

Passed a-full on autobuilder:

https://valkyrie.yoctoproject.org/#/builders/29/builds/332

The following changes since commit a1b28a88bc7697371ab166b18587b615d6d39c8e:

  image.bbclass: Drop support for ImageQAFailed exceptions in image_qa (2024-10-16 06:21:24 -0700)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

Anuj Mittal (1):
  sqlite3: upgrade 3.45.1 -> 3.45.3

Bruce Ashfield (2):
  linux-yocto/6.6: update to v6.6.52
  linux-yocto/6.6: update to v6.6.54

Jiaying Song (1):
  liba52: fix do_fetch error

Jonas Gorski (1):
  rootfs-postcommands.bbclass: make opkg status reproducible

Peter Marko (1):
  openssl: patch CVE-2024-9143

Rohini Sangam (1):
  vim: Upgrade 9.1.0698 -> 9.1.0764

Ross Burton (1):
  icu: update patch Upstream-Status

Sergei Zhmylev (1):
  lsb-release: fix Distro Codename shell escaping

Shunsuke Tokumoto (1):
  python3-setuptools: Add "python:setuptools" to CVE_PRODUCT

aszh07 (1):
  ffmpeg: Add "libswresample libavcodec" to CVE_PRODUCT

 .../rootfs-postcommands.bbclass               |   4 +
 .../openssl/openssl/CVE-2024-9143.patch       | 202 ++++++++++++++++++
 .../openssl/openssl_3.2.3.bb                  |   1 +
 .../python/python3-setuptools_69.1.1.bb       |   2 +
 meta/recipes-extended/lsb/lsb-release_1.4.bb  |   2 +-
 .../linux/linux-yocto-rt_6.6.bb               |   6 +-
 .../linux/linux-yocto-tiny_6.6.bb             |   6 +-
 meta/recipes-kernel/linux/linux-yocto_6.6.bb  |  28 +--
 .../recipes-multimedia/ffmpeg/ffmpeg_6.1.1.bb |   2 +
 .../recipes-multimedia/liba52/liba52_0.7.4.bb |   2 +-
 .../icu/icu/fix-install-manx.patch            |   4 +-
 .../{sqlite3_3.45.1.bb => sqlite3_3.45.3.bb}  |   2 +-
 meta/recipes-support/vim/vim.inc              |   4 +-
 13 files changed, 237 insertions(+), 28 deletions(-)
 create mode 100755 meta/recipes-connectivity/openssl/openssl/CVE-2024-9143.patch
 rename meta/recipes-support/sqlite/{sqlite3_3.45.1.bb => sqlite3_3.45.3.bb} (69%)

-- 
2.34.1



^ permalink raw reply	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 00/11] Patch review
@ 2025-05-28 14:43 Steve Sakoman
  0 siblings, 0 replies; 25+ messages in thread
From: Steve Sakoman @ 2025-05-28 14:43 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Friday, May 30

Passed a-full on autobuilder:

https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/1672

The following changes since commit 29d920f4c2249df7a69f00100924b4525e03c0d9:

  libatomic-ops: Update GITHUB_BASE_URI (2025-05-20 08:59:39 -0700)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

Ashish Sharma (1):
  libsoup: patch CVE-2025-4476

Divya Chellam (1):
  ruby: fix CVE-2025-27221

Divyanshu Rathore (1):
  ffmpeg: upgrade 6.1.1 -> 6.1.2

Harish Sadineni (2):
  binutils: Fix CVE-2025-1179
  binutils: set CVE_STATUS for CVE-2025-1180

Rogerio Guerra Borin (1):
  u-boot: ensure keys are generated before assembling U-Boot FIT image

Vijay Anusuri (4):
  libsoup-2.4: Fix CVE-2025-32910
  libsoup-2.4: Fix CVE-2025-32911 & CVE-2025-32913
  libsoup-2.4: Fix CVE-2025-32912
  libsoup-2.4: Fix CVE-2025-32914

Virendra Thakur (1):
  util-linux: Add fix to isolate test fstab entries using CUSTOM_FSTAB

 meta/classes-recipe/uboot-sign.bbclass        |    2 +
 meta/recipes-core/util-linux/util-linux.inc   |    1 +
 .../util-linux/fstab-isolation.patch          |  448 +++++++
 .../binutils/binutils-2.42.inc                |    3 +
 .../binutils/binutils/CVE-2025-1179-pre.patch | 1086 +++++++++++++++++
 .../binutils/binutils/CVE-2025-1179.patch     |  269 ++++
 .../ruby/ruby/CVE-2025-27221-0001.patch       |   57 +
 .../ruby/ruby/CVE-2025-27221-0002.patch       |   73 ++
 meta/recipes-devtools/ruby/ruby_3.3.5.bb      |    2 +
 .../ffmpeg/ffmpeg/CVE-2024-32230.patch        |   36 -
 .../ffmpeg/ffmpeg/CVE-2024-35366.patch        |   35 -
 .../ffmpeg/ffmpeg/CVE-2024-36613.patch        |   37 -
 .../ffmpeg/ffmpeg/CVE-2024-36616.patch        |   35 -
 .../ffmpeg/ffmpeg/CVE-2024-36617.patch        |   36 -
 .../ffmpeg/ffmpeg/CVE-2024-36619.patch        |   36 -
 .../ffmpeg/ffmpeg/CVE-2024-7055.patch         |   38 -
 .../ffmpeg/ffmpeg/vulkan_av1_stable_API.patch |   40 +-
 .../{ffmpeg_6.1.1.bb => ffmpeg_6.1.2.bb}      |    9 +-
 .../libsoup-2.4/CVE-2025-32910-1.patch        |   97 ++
 .../libsoup-2.4/CVE-2025-32910-2.patch        |  148 +++
 .../libsoup-2.4/CVE-2025-32910-3.patch        |   26 +
 .../CVE-2025-32911_CVE-2025-32913-1.patch     |   72 ++
 .../CVE-2025-32911_CVE-2025-32913-2.patch     |   44 +
 .../libsoup-2.4/CVE-2025-32912-1.patch        |   41 +
 .../libsoup-2.4/CVE-2025-32912-2.patch        |   30 +
 .../libsoup/libsoup-2.4/CVE-2025-32914.patch  |  137 +++
 .../libsoup/libsoup-2.4_2.74.3.bb             |    8 +
 .../libsoup/libsoup-3.4.4/CVE-2025-4476.patch |   38 +
 meta/recipes-support/libsoup/libsoup_3.4.4.bb |    1 +
 29 files changed, 2604 insertions(+), 281 deletions(-)
 create mode 100644 meta/recipes-core/util-linux/util-linux/fstab-isolation.patch
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-1179-pre.patch
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-1179.patch
 create mode 100644 meta/recipes-devtools/ruby/ruby/CVE-2025-27221-0001.patch
 create mode 100644 meta/recipes-devtools/ruby/ruby/CVE-2025-27221-0002.patch
 delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-32230.patch
 delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-35366.patch
 delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-36613.patch
 delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-36616.patch
 delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-36617.patch
 delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-36619.patch
 delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-7055.patch
 rename meta/recipes-multimedia/ffmpeg/{ffmpeg_6.1.1.bb => ffmpeg_6.1.2.bb} (96%)
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2025-32910-1.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2025-32910-2.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2025-32910-3.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2025-32911_CVE-2025-32913-1.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2025-32911_CVE-2025-32913-2.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2025-32912-1.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2025-32912-2.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2025-32914.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-3.4.4/CVE-2025-4476.patch

-- 
2.43.0



^ permalink raw reply	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 00/11] Patch review
@ 2025-07-04 15:10 Steve Sakoman
  0 siblings, 0 replies; 25+ messages in thread
From: Steve Sakoman @ 2025-07-04 15:10 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Tuesday, July 8

Passed a-full on autobuilder:

https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/1948

The following changes since commit 175cd54fd57266d7dea07121861a4f15be00a882:

  tcf-agent: correct the SRC_URI (2025-07-03 09:01:28 -0700)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

Archana Polampalli (6):
  xwayland: fix CVE-2025-49175
  xwayland: fix CVE-2025-49176
  xwayland: fix CVE-2025-49177
  xwayland: fix CVE-2025-49178
  xwayland: fix CVE-2025-49179
  xwayland: fix CVE-2025-49180

Divya Chellam (5):
  libarchive: fix CVE-2025-5914
  libarchive: fix CVE-2025-5915
  libarchive: fix CVE-2025-5916
  libarchive: fix CVE-2025-5917
  libarchive: fix CVE-2025-5918

 .../libarchive/libarchive/CVE-2025-5914.patch |  48 +++
 .../libarchive/libarchive/CVE-2025-5915.patch | 217 ++++++++++++
 .../libarchive/libarchive/CVE-2025-5916.patch | 116 +++++++
 .../libarchive/libarchive/CVE-2025-5917.patch |  54 +++
 .../libarchive/CVE-2025-5918-0001.patch       | 326 ++++++++++++++++++
 .../libarchive/CVE-2025-5918-0002.patch       | 222 ++++++++++++
 .../libarchive/libarchive_3.7.9.bb            |   6 +
 .../xwayland/xwayland/CVE-2025-49175.patch    |  92 +++++
 .../xwayland/CVE-2025-49176-0001.patch        |  93 +++++
 .../xwayland/CVE-2025-49176-0002.patch        |  38 ++
 .../xwayland/xwayland/CVE-2025-49177.patch    |  55 +++
 .../xwayland/xwayland/CVE-2025-49178.patch    |  50 +++
 .../xwayland/xwayland/CVE-2025-49179.patch    |  69 ++++
 .../xwayland/xwayland/CVE-2025-49180.patch    |  45 +++
 .../xwayland/xwayland_23.2.5.bb               |   7 +
 15 files changed, 1438 insertions(+)
 create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2025-5914.patch
 create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2025-5915.patch
 create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2025-5916.patch
 create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2025-5917.patch
 create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2025-5918-0001.patch
 create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2025-5918-0002.patch
 create mode 100644 meta/recipes-graphics/xwayland/xwayland/CVE-2025-49175.patch
 create mode 100644 meta/recipes-graphics/xwayland/xwayland/CVE-2025-49176-0001.patch
 create mode 100644 meta/recipes-graphics/xwayland/xwayland/CVE-2025-49176-0002.patch
 create mode 100644 meta/recipes-graphics/xwayland/xwayland/CVE-2025-49177.patch
 create mode 100644 meta/recipes-graphics/xwayland/xwayland/CVE-2025-49178.patch
 create mode 100644 meta/recipes-graphics/xwayland/xwayland/CVE-2025-49179.patch
 create mode 100644 meta/recipes-graphics/xwayland/xwayland/CVE-2025-49180.patch

-- 
2.43.0



^ permalink raw reply	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 00/11] Patch review
@ 2025-07-30 21:28 Steve Sakoman
  0 siblings, 0 replies; 25+ messages in thread
From: Steve Sakoman @ 2025-07-30 21:28 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Friday, August 1

Passed a-full on autobuilder:

https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/2114

The following changes since commit c374e6cfcdd2c8ba17d82ffcfdeb97d21144e2bf:

  mtools: upgrade 4.0.48 -> 4.0.49 (2025-07-25 06:13:34 -0700)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

Aleksandar Nikolic (1):
  scripts/install-buildtools: Update to 5.0.11

Fabio Berton (1):
  linux-libc-headers: Fix invalid conversion in cn_proc.h

Peter Marko (9):
  gnutls: patch CVE-2025-32989
  gnutls: patch read buffer overrun in the "pre_shared_key" extension
  gnutls: patch reject zero-length version in certificate request
  gnutls: patch CVE-2025-32988
  gnutls: patch CVE-2025-32990
  gnutls: patch CVE-2025-6395
  ncurses: patch CVE-2025-6141
  libxml2: patch CVE-2025-6170
  glibc: fix CVE-2025-8058

 meta/recipes-core/glibc/glibc-version.inc     |    2 +-
 meta/recipes-core/glibc/glibc_2.39.bb         |    2 +-
 .../libxml/libxml2/CVE-2025-6170.patch        |  103 +
 meta/recipes-core/libxml/libxml2_2.12.10.bb   |    1 +
 .../ncurses/files/CVE-2025-6141.patch         |   25 +
 meta/recipes-core/ncurses/ncurses_6.4.bb      |    1 +
 ...-Fix-invalid-conversion-in-cn_proc.h.patch |   40 +
 .../linux-libc-headers_6.6.bb                 |    1 +
 ...fer-overrun-in-the-pre_shared_key-ex.patch |   34 +
 ...-length-version-in-certificate-reque.patch |   37 +
 .../04939b75417cc95b7372c6f208c4bda4579bdc34  |  Bin 0 -> 1782 bytes
 .../3e94dcdff862ef5d6db8b5cc8e59310b5f0cdfe2  |  Bin 0 -> 830 bytes
 .../5477db1bb507a35e8833c758ce344f4b5b246d8e  |  Bin 0 -> 111 bytes
 .../gnutls/gnutls/CVE-2025-32988.patch        |   58 +
 .../gnutls/gnutls/CVE-2025-32989.patch        |   50 +
 .../gnutls/gnutls/CVE-2025-32990.patch        | 2109 +++++++++++++++++
 .../gnutls/gnutls/CVE-2025-6395.patch         |  299 +++
 meta/recipes-support/gnutls/gnutls_3.8.4.bb   |   15 +
 scripts/install-buildtools                    |    4 +-
 19 files changed, 2777 insertions(+), 4 deletions(-)
 create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2025-6170.patch
 create mode 100644 meta/recipes-core/ncurses/files/CVE-2025-6141.patch
 create mode 100644 meta/recipes-kernel/linux-libc-headers/linux-libc-headers/0001-connector-Fix-invalid-conversion-in-cn_proc.h.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/0001-psk-fix-read-buffer-overrun-in-the-pre_shared_key-ex.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/0001-x509-reject-zero-length-version-in-certificate-reque.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/04939b75417cc95b7372c6f208c4bda4579bdc34
 create mode 100644 meta/recipes-support/gnutls/gnutls/3e94dcdff862ef5d6db8b5cc8e59310b5f0cdfe2
 create mode 100644 meta/recipes-support/gnutls/gnutls/5477db1bb507a35e8833c758ce344f4b5b246d8e
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2025-32988.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2025-32989.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2025-32990.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2025-6395.patch

-- 
2.43.0



^ permalink raw reply	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 00/11] Patch review
@ 2025-09-25 13:40 Steve Sakoman
  0 siblings, 0 replies; 25+ messages in thread
From: Steve Sakoman @ 2025-09-25 13:40 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Monday, September 29

Passed a-full on autobuilder:

https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/2436

The following changes since commit 4cf131ebd157b79226533b5a5074691dd0e1a4ab:

  buildtools-tarball: fix unbound variable issues under 'set -u' (2025-09-17 09:32:52 -0700)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

Adrian Freihofer (2):
  llvm: update from 18.1.6 to 18.1.8
  llvm: fix build with gcc-15

AshishKumar Mishra (2):
  systemd: backport fix for handle USE_NLS from master
  p11-kit: backport fix for handle USE_NLS from master

Chris Laplante (1):
  util-linux: use ${B} instead of ${WORKDIR}/build, to fix building
    under devtool

Martin Jansa (2):
  sanity.conf: Update minimum bitbake version to 2.8.1
  lib/oe/utils: use multiprocessing from bb

Nitin Wankhade (1):
  examples: genl: fix wrong attribute size

Philip Lorenz (1):
  shared-mime-info: Handle USE_NLS

Ross Burton (1):
  libxslt: apply patch for CVE-2025-7424

Yogita Urade (1):
  curl: fix CVE-2025-9086

 meta/conf/sanity.conf                         |   2 +-
 meta/lib/oe/utils.py                          |   3 +-
 meta/recipes-core/systemd/systemd_255.21.bb   |   1 +
 .../util-linux/util-linux_2.39.3.bb           |   2 +-
 ...36-Add-cstdint-to-SmallVector-101761.patch |  28 +++++
 ...cstdint-in-AMDGPUMCTargetDesc-101766.patch |  23 ++++
 ...-include-to-X86MCTargetDesc.h-123320.patch |  32 ++++++
 .../llvm/{llvm_18.1.6.bb => llvm_18.1.8.bb}   |   5 +-
 ...amples-genl-fix-wrong-attribute-size.patch |  44 ++++++++
 meta/recipes-extended/libmnl/libmnl_1.0.5.bb  |   5 +-
 .../curl/curl/CVE-2025-9086.patch             |  55 ++++++++++
 meta/recipes-support/curl/curl_8.7.1.bb       |   1 +
 .../gnome-libxslt-bug-139-apple-fix.diff      | 103 ++++++++++++++++++
 .../recipes-support/libxslt/libxslt_1.1.43.bb |   3 +-
 .../recipes-support/p11-kit/p11-kit_0.25.3.bb |   1 +
 .../shared-mime-info/shared-mime-info_2.4.bb  |   5 +-
 16 files changed, 306 insertions(+), 7 deletions(-)
 create mode 100644 meta/recipes-devtools/llvm/llvm/0036-Add-cstdint-to-SmallVector-101761.patch
 create mode 100644 meta/recipes-devtools/llvm/llvm/0037-Include-cstdint-in-AMDGPUMCTargetDesc-101766.patch
 create mode 100644 meta/recipes-devtools/llvm/llvm/0038-Add-missing-include-to-X86MCTargetDesc.h-123320.patch
 rename meta/recipes-devtools/llvm/{llvm_18.1.6.bb => llvm_18.1.8.bb} (94%)
 create mode 100644 meta/recipes-extended/libmnl/files/0001-examples-genl-fix-wrong-attribute-size.patch
 create mode 100644 meta/recipes-support/curl/curl/CVE-2025-9086.patch
 create mode 100644 meta/recipes-support/libxslt/files/gnome-libxslt-bug-139-apple-fix.diff

-- 
2.43.0



^ permalink raw reply	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 00/11] Patch review
@ 2026-03-07 22:52 Yoann Congal
  2026-03-09  8:18 ` Paul Barker
  0 siblings, 1 reply; 25+ messages in thread
From: Yoann Congal @ 2026-03-07 22:52 UTC (permalink / raw)
  To: openembedded-core

Note: this series contains a major OpenSSL upgrade (agreed by YP TSC).

Please review this set of changes for scarthgap and have comments back by
end of day Tuesday, March 10.

Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/3349
(Ignore the warning about Centos Stream9, its support is a work in progress for scarthgap)

I also did a full meta-oe build (to check for build failure with the
OpenSSL upgrade)
https://autobuilder.yoctoproject.org/valkyrie/#/builders/81/builds/1342
(the warnings are unrelated to this series)

The following changes since commit a9a785d7fa0cfe2a9087dbcde0ef9f0d2a441375:

  build-appliance-image: Update to scarthgap head revision (2026-02-27 17:45:15 +0000)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

for you to fetch changes up to fd8a140eb0742bbc12a23e36c9d24378bc0f462d:

  busybox: Fixes CVE-2025-60876 (2026-03-06 23:58:42 +0100)

----------------------------------------------------------------

Hugo SIMELIERE (2):
  zlib: Fix CVE-2026-27171
  harfbuzz: Fix CVE-2026-22693

Livin Sunny (1):
  busybox: Fixes CVE-2025-60876

Paul Barker (1):
  create-pull-request: Keep commit hash to be pulled in cover email

Peter Marko (3):
  ffmpeg: set status for CVE-2025-10256
  ffmpeg: set status for CVE-2025-12343
  openssl: upgrade 3.2.6 -> 3.5.5

Shaik Moin (1):
  gdk-pixbuf: Fix CVE-2025-6199

Tom Hochstein (1):
  uboot-config: Fix devtool modify

Yoann Congal (2):
  scripts/install-buildtools: Update to 5.0.16
  README: Add scarthgap subject-prefix to git-send-email suggestion

 README.OE-Core.md                             |  2 +-
 meta/classes-recipe/uboot-config.bbclass      |  2 +-
 .../openssl/files/environment.d-openssl.sh    |  9 ++-
 ...ke-history-reporting-when-test-fails.patch | 32 ++++----
 ...1-Configure-do-not-tweak-mips-cflags.patch |  4 +-
 ...sysroot-and-debug-prefix-map-from-co.patch | 26 ++++---
 .../0001-extend-check_cwm-test-timeout.patch  | 32 ++++++++
 .../openssl/openssl/CVE-2024-41996.patch      | 44 -----------
 .../openssl/openssl/CVE-2025-15468.patch      | 39 ----------
 .../openssl/openssl/CVE-2025-69419.patch      | 61 ---------------
 .../{openssl_3.2.6.bb => openssl_3.5.5.bb}    | 75 ++++++++++++-------
 .../busybox/busybox/CVE-2025-60876.patch      | 42 +++++++++++
 meta/recipes-core/busybox/busybox_1.36.1.bb   |  1 +
 .../zlib/zlib/CVE-2026-27171.patch            | 63 ++++++++++++++++
 meta/recipes-core/zlib/zlib_1.3.1.bb          |  1 +
 .../gdk-pixbuf/gdk-pixbuf/CVE-2025-6199.patch | 36 +++++++++
 .../gdk-pixbuf/gdk-pixbuf_2.42.12.bb          |  1 +
 .../harfbuzz/files/CVE-2026-22693.patch       | 33 ++++++++
 .../harfbuzz/harfbuzz_8.3.0.bb                |  4 +-
 .../recipes-multimedia/ffmpeg/ffmpeg_6.1.4.bb |  2 +-
 scripts/create-pull-request                   |  2 +-
 scripts/install-buildtools                    |  4 +-
 22 files changed, 305 insertions(+), 210 deletions(-)
 create mode 100644 meta/recipes-connectivity/openssl/openssl/0001-extend-check_cwm-test-timeout.patch
 delete mode 100644 meta/recipes-connectivity/openssl/openssl/CVE-2024-41996.patch
 delete mode 100644 meta/recipes-connectivity/openssl/openssl/CVE-2025-15468.patch
 delete mode 100644 meta/recipes-connectivity/openssl/openssl/CVE-2025-69419.patch
 rename meta/recipes-connectivity/openssl/{openssl_3.2.6.bb => openssl_3.5.5.bb} (76%)
 create mode 100644 meta/recipes-core/busybox/busybox/CVE-2025-60876.patch
 create mode 100644 meta/recipes-core/zlib/zlib/CVE-2026-27171.patch
 create mode 100644 meta/recipes-gnome/gdk-pixbuf/gdk-pixbuf/CVE-2025-6199.patch
 create mode 100644 meta/recipes-graphics/harfbuzz/files/CVE-2026-22693.patch



^ permalink raw reply	[flat|nested] 25+ messages in thread

* Re: [OE-core][scarthgap 00/11] Patch review
  2026-03-07 22:52 Yoann Congal
@ 2026-03-09  8:18 ` Paul Barker
  0 siblings, 0 replies; 25+ messages in thread
From: Paul Barker @ 2026-03-09  8:18 UTC (permalink / raw)
  To: yoann.congal, openembedded-core

[-- Attachment #1: Type: text/plain, Size: 2171 bytes --]

On Sat, 2026-03-07 at 23:52 +0100, Yoann Congal via
lists.openembedded.org wrote:
> Note: this series contains a major OpenSSL upgrade (agreed by YP TSC).
> 
> Please review this set of changes for scarthgap and have comments back by
> end of day Tuesday, March 10.
> 
> Passed a-full on autobuilder:
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/3349
> (Ignore the warning about Centos Stream9, its support is a work in progress for scarthgap)
> 
> I also did a full meta-oe build (to check for build failure with the
> OpenSSL upgrade)
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/81/builds/1342
> (the warnings are unrelated to this series)
> 
> The following changes since commit a9a785d7fa0cfe2a9087dbcde0ef9f0d2a441375:
> 
>   build-appliance-image: Update to scarthgap head revision (2026-02-27 17:45:15 +0000)
> 
> are available in the Git repository at:
> 
>   https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
>   https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut
> 
> for you to fetch changes up to fd8a140eb0742bbc12a23e36c9d24378bc0f462d:
> 
>   busybox: Fixes CVE-2025-60876 (2026-03-06 23:58:42 +0100)
> 
> ----------------------------------------------------------------
> 
> Hugo SIMELIERE (2):
>   zlib: Fix CVE-2026-27171
>   harfbuzz: Fix CVE-2026-22693
> 
> Livin Sunny (1):
>   busybox: Fixes CVE-2025-60876
> 
> Paul Barker (1):
>   create-pull-request: Keep commit hash to be pulled in cover email
> 
> Peter Marko (3):
>   ffmpeg: set status for CVE-2025-10256
>   ffmpeg: set status for CVE-2025-12343
>   openssl: upgrade 3.2.6 -> 3.5.5
> 
> Shaik Moin (1):
>   gdk-pixbuf: Fix CVE-2025-6199
> 
> Tom Hochstein (1):
>   uboot-config: Fix devtool modify
> 
> Yoann Congal (2):
>   scripts/install-buildtools: Update to 5.0.16
>   README: Add scarthgap subject-prefix to git-send-email suggestion

Hi Yoann,

We need to make sure that the openssl update is clearly announced in the
weekly status and the release notes for 5.0.17. Otherwise, all LGTM!

Best regards,

-- 
Paul Barker


[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 252 bytes --]

^ permalink raw reply	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 00/11] Patch review
@ 2026-03-29 22:46 Yoann Congal
  2026-03-30  7:33 ` Yoann Congal
  2026-04-20  8:44 ` Joao Marcos Costa
  0 siblings, 2 replies; 25+ messages in thread
From: Yoann Congal @ 2026-03-29 22:46 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Tuesday, March 31.

Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/3546
Note: This particular build had a gnutls patch that I removed because it needed a small change[0].
Build (currently running) without the gnutls patch: https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/3551

[0]: https://lore.kernel.org/openembedded-core/DHFLXG1K82R7.3EOQRZ2H6KW8Q@smile.fr/T/#t

The following changes since commit 41597b5260fb5ca811d0fb4ae7e65246d61734eb:

  Revert "scripts/install-buildtools: Update to 5.0.16" (2026-03-26 09:48:20 +0000)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

for you to fetch changes up to e6f3b2e043259650d80fb6f761797c5cf5587eb5:

  python3-pyopenssl: Fix CVE-2026-27459 (2026-03-30 00:09:38 +0200)

----------------------------------------------------------------

João Marcos Costa (Schneider Electric) (1):
  spdx: add option to include only compiled sources

Martin Jansa (3):
  dtc: backport fix for build with glibc-2.43
  elfutils: don't add -Werror to avoid discarded-qualifiers
  binutils: backport patch to fix build with glibc-2.43 on host

Michael Halstead (2):
  yocto-uninative: Update to 5.0 for needed patchelf updates
  yocto-uninative: Update to 5.1 for glibc 2.43

Nguyen Dat Tho (1):
  python3-cryptography: Fix CVE-2026-26007

Paul Barker (1):
  tzdata,tzcode-native: Upgrade 2025b -> 2025c

Richard Purdie (1):
  pseudo: Add fix for glibc 2.43

Vijay Anusuri (2):
  python3-pyopenssl: Fix CVE-2026-27448
  python3-pyopenssl: Fix CVE-2026-27459

 meta/classes/spdx-common.bbclass              |   3 +
 meta/conf/distro/include/yocto-uninative.inc  |  10 +-
 meta/lib/oe/spdx30_tasks.py                   |  12 ++
 .../binutils/binutils-2.42.inc                |   1 +
 ...tect-against-standard-library-macros.patch |  31 ++++
 .../elfutils/elfutils_0.191.bb                |   1 +
 ...001-config-eu.am-do-not-force-Werror.patch |  34 ++++
 meta/recipes-devtools/pseudo/pseudo_git.bb    |   2 +-
 .../python3-cryptography/CVE-2026-26007.patch | 149 ++++++++++++++++++
 .../python/python3-cryptography_42.0.5.bb     |   1 +
 .../python3-pyopenssl/CVE-2026-27448.patch    | 124 +++++++++++++++
 .../python3-pyopenssl/CVE-2026-27459.patch    | 109 +++++++++++++
 .../python/python3-pyopenssl_24.0.0.bb        |   5 +
 meta/recipes-extended/timezone/timezone.inc   |   6 +-
 .../0001-Fix-discarded-const-qualifiers.patch |  85 ++++++++++
 meta/recipes-kernel/dtc/dtc_1.7.0.bb          |   1 +
 16 files changed, 565 insertions(+), 9 deletions(-)
 create mode 100644 meta/recipes-devtools/binutils/binutils/0022-gprofng-protect-against-standard-library-macros.patch
 create mode 100644 meta/recipes-devtools/elfutils/files/0001-config-eu.am-do-not-force-Werror.patch
 create mode 100644 meta/recipes-devtools/python/python3-cryptography/CVE-2026-26007.patch
 create mode 100644 meta/recipes-devtools/python/python3-pyopenssl/CVE-2026-27448.patch
 create mode 100644 meta/recipes-devtools/python/python3-pyopenssl/CVE-2026-27459.patch
 create mode 100644 meta/recipes-kernel/dtc/dtc/0001-Fix-discarded-const-qualifiers.patch



^ permalink raw reply	[flat|nested] 25+ messages in thread

* Re: [OE-core][scarthgap 00/11] Patch review
  2026-03-29 22:46 [OE-core][scarthgap 00/11] Patch review Yoann Congal
@ 2026-03-30  7:33 ` Yoann Congal
  2026-04-20  8:44 ` Joao Marcos Costa
  1 sibling, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-03-30  7:33 UTC (permalink / raw)
  To: Yoann Congal, openembedded-core

On Mon Mar 30, 2026 at 12:46 AM CEST, Yoann Congal wrote:
> Please review this set of changes for scarthgap and have comments back by
> end of day Tuesday, March 31.
>
> Passed a-full on autobuilder:
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/3546
> Note: This particular build had a gnutls patch that I removed because it needed a small change[0].
> Build (currently running) without the gnutls patch: https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/3551

That second build is successful. (Only a warning from VNC integration on
autobuilder, I'll send a patch)

> [0]: https://lore.kernel.org/openembedded-core/DHFLXG1K82R7.3EOQRZ2H6KW8Q@smile.fr/T/#t
>
> The following changes since commit 41597b5260fb5ca811d0fb4ae7e65246d61734eb:
>
>   Revert "scripts/install-buildtools: Update to 5.0.16" (2026-03-26 09:48:20 +0000)
>
> are available in the Git repository at:
>
>   https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
>   https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut
>
> for you to fetch changes up to e6f3b2e043259650d80fb6f761797c5cf5587eb5:
>
>   python3-pyopenssl: Fix CVE-2026-27459 (2026-03-30 00:09:38 +0200)
>
> ----------------------------------------------------------------
>
> João Marcos Costa (Schneider Electric) (1):
>   spdx: add option to include only compiled sources
>
> Martin Jansa (3):
>   dtc: backport fix for build with glibc-2.43
>   elfutils: don't add -Werror to avoid discarded-qualifiers
>   binutils: backport patch to fix build with glibc-2.43 on host
>
> Michael Halstead (2):
>   yocto-uninative: Update to 5.0 for needed patchelf updates
>   yocto-uninative: Update to 5.1 for glibc 2.43
>
> Nguyen Dat Tho (1):
>   python3-cryptography: Fix CVE-2026-26007
>
> Paul Barker (1):
>   tzdata,tzcode-native: Upgrade 2025b -> 2025c
>
> Richard Purdie (1):
>   pseudo: Add fix for glibc 2.43
>
> Vijay Anusuri (2):
>   python3-pyopenssl: Fix CVE-2026-27448
>   python3-pyopenssl: Fix CVE-2026-27459
>
>  meta/classes/spdx-common.bbclass              |   3 +
>  meta/conf/distro/include/yocto-uninative.inc  |  10 +-
>  meta/lib/oe/spdx30_tasks.py                   |  12 ++
>  .../binutils/binutils-2.42.inc                |   1 +
>  ...tect-against-standard-library-macros.patch |  31 ++++
>  .../elfutils/elfutils_0.191.bb                |   1 +
>  ...001-config-eu.am-do-not-force-Werror.patch |  34 ++++
>  meta/recipes-devtools/pseudo/pseudo_git.bb    |   2 +-
>  .../python3-cryptography/CVE-2026-26007.patch | 149 ++++++++++++++++++
>  .../python/python3-cryptography_42.0.5.bb     |   1 +
>  .../python3-pyopenssl/CVE-2026-27448.patch    | 124 +++++++++++++++
>  .../python3-pyopenssl/CVE-2026-27459.patch    | 109 +++++++++++++
>  .../python/python3-pyopenssl_24.0.0.bb        |   5 +
>  meta/recipes-extended/timezone/timezone.inc   |   6 +-
>  .../0001-Fix-discarded-const-qualifiers.patch |  85 ++++++++++
>  meta/recipes-kernel/dtc/dtc_1.7.0.bb          |   1 +
>  16 files changed, 565 insertions(+), 9 deletions(-)
>  create mode 100644 meta/recipes-devtools/binutils/binutils/0022-gprofng-protect-against-standard-library-macros.patch
>  create mode 100644 meta/recipes-devtools/elfutils/files/0001-config-eu.am-do-not-force-Werror.patch
>  create mode 100644 meta/recipes-devtools/python/python3-cryptography/CVE-2026-26007.patch
>  create mode 100644 meta/recipes-devtools/python/python3-pyopenssl/CVE-2026-27448.patch
>  create mode 100644 meta/recipes-devtools/python/python3-pyopenssl/CVE-2026-27459.patch
>  create mode 100644 meta/recipes-kernel/dtc/dtc/0001-Fix-discarded-const-qualifiers.patch


-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 25+ messages in thread

* Re: [OE-core][scarthgap 00/11] Patch review
  2026-03-29 22:46 [OE-core][scarthgap 00/11] Patch review Yoann Congal
  2026-03-30  7:33 ` Yoann Congal
@ 2026-04-20  8:44 ` Joao Marcos Costa
  2026-04-20  9:21   ` Yoann Congal
  1 sibling, 1 reply; 25+ messages in thread
From: Joao Marcos Costa @ 2026-04-20  8:44 UTC (permalink / raw)
  To: openembedded-core; +Cc: Yoann Congal

Hello, Yoan


On 3/30/26 00:46, Yoann Congal via lists.openembedded.org wrote:
> Please review this set of changes for scarthgap and have comments back by
> end of day Tuesday, March 31.
> 
> Passed a-full on autobuilder:
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/3546
> Note: This particular build had a gnutls patch that I removed because it needed a small change[0].
> Build (currently running) without the gnutls patch: https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/3551
> 
> [0]: https://lore.kernel.org/openembedded-core/DHFLXG1K82R7.3EOQRZ2H6KW8Q@smile.fr/T/#t
> 
> The following changes since commit 41597b5260fb5ca811d0fb4ae7e65246d61734eb:
> 
>    Revert "scripts/install-buildtools: Update to 5.0.16" (2026-03-26 09:48:20 +0000)
> 
> are available in the Git repository at:
> 
>    https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
>    https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut
> 
> for you to fetch changes up to e6f3b2e043259650d80fb6f761797c5cf5587eb5:
> 
>    python3-pyopenssl: Fix CVE-2026-27459 (2026-03-30 00:09:38 +0200)
> 
> ----------------------------------------------------------------
> 
> João Marcos Costa (Schneider Electric) (1):
>    spdx: add option to include only compiled sources
> 
> Martin Jansa (3):
>    dtc: backport fix for build with glibc-2.43
>    elfutils: don't add -Werror to avoid discarded-qualifiers
>    binutils: backport patch to fix build with glibc-2.43 on host
> 
> Michael Halstead (2):
>    yocto-uninative: Update to 5.0 for needed patchelf updates
>    yocto-uninative: Update to 5.1 for glibc 2.43
> 
> Nguyen Dat Tho (1):
>    python3-cryptography: Fix CVE-2026-26007
> 
> Paul Barker (1):
>    tzdata,tzcode-native: Upgrade 2025b -> 2025c
> 
> Richard Purdie (1):
>    pseudo: Add fix for glibc 2.43
> 
> Vijay Anusuri (2):
>    python3-pyopenssl: Fix CVE-2026-27448
>    python3-pyopenssl: Fix CVE-2026-27459
(...)

Was the commit below not picked, or am I missing something?

commit b24d5cda19136fb8120154279eedd55d162b4640
Author: João Marcos Costa (Schneider Electric) 
<joaomarcos.costa@bootlin.com>
Date:   Fri Apr 3 11:32:30 2026 +0200

     linux-yocto/6.6: update CVE exclusions (6.6.123)

     This new version of cve-exclusion_6.6.inc was generated with oe-core's
     latest version of the generate-cve-exclusions.py.

     Regarding the database used and how this file was generated:

     Generated at 2026-04-03 09:30:32.247568+00:00 for kernel version 
6.6.123
     From cvelistV5 cve_2026-04-03_0700Z

     The backporting of the generate-cve-exclusions.py script from master to
     Scarthgap is handled in a different patch.

     Signed-off-by: João Marcos Costa (Schneider Electric) 
<joaomarcos.costa@bootlin.com>

However, I see the commit below, prior to this one, was kept:

linux/generate-cve-exclusions: backport script from master branch

I'm not really used to the backports schedule/workflow, so please excuse 
me if I misinterpreted something.

Thanks!

-- 
Best regards,
João Marcos Costa


^ permalink raw reply	[flat|nested] 25+ messages in thread

* Re: [OE-core][scarthgap 00/11] Patch review
  2026-04-20  8:44 ` Joao Marcos Costa
@ 2026-04-20  9:21   ` Yoann Congal
  2026-04-20 10:51     ` Joao Marcos Costa
  0 siblings, 1 reply; 25+ messages in thread
From: Yoann Congal @ 2026-04-20  9:21 UTC (permalink / raw)
  To: Joao Marcos Costa, openembedded-core

On Mon Apr 20, 2026 at 10:44 AM CEST, Joao Marcos Costa wrote:
> Hello, Yoan
>
>
> On 3/30/26 00:46, Yoann Congal via lists.openembedded.org wrote:
>> Please review this set of changes for scarthgap and have comments back by
>> end of day Tuesday, March 31.
> (...)
>
> Was the commit below not picked, or am I missing something?
>
> commit b24d5cda19136fb8120154279eedd55d162b4640
> Author: João Marcos Costa (Schneider Electric) 
> <joaomarcos.costa@bootlin.com>
> Date:   Fri Apr 3 11:32:30 2026 +0200
>
>      linux-yocto/6.6: update CVE exclusions (6.6.123)
>
>      This new version of cve-exclusion_6.6.inc was generated with oe-core's
>      latest version of the generate-cve-exclusions.py.
>
>      Regarding the database used and how this file was generated:
>
>      Generated at 2026-04-03 09:30:32.247568+00:00 for kernel version 
> 6.6.123
>      From cvelistV5 cve_2026-04-03_0700Z
>
>      The backporting of the generate-cve-exclusions.py script from master to
>      Scarthgap is handled in a different patch.
>
>      Signed-off-by: João Marcos Costa (Schneider Electric) 
> <joaomarcos.costa@bootlin.com>
>
> However, I see the commit below, prior to this one, was kept:
>
> linux/generate-cve-exclusions: backport script from master branch
>
> I'm not really used to the backports schedule/workflow, so please excuse 
> me if I misinterpreted something.
>
> Thanks!

This patch triggered a problem in our infra. I received it directly from
you but it is missing from lore. And lore feeds patchwork, and I use
patchwork to prepare my review branch...

This is a known problem: 16167 – Missing (big) patch in patchwork
https://bugzilla.yoctoproject.org/show_bug.cgi?id=16167

I've reopened and added your patch to the bug log.

I will now integrate your patch in my review branch.

Thanks for the report, otherwise I would have missed it.

I'll try to check for this issue in the future but this will be hard to
spot. If you send a similar patch in the future don't hesitate to ping
me if you see it missing during the patch review period.

Regards,
-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 25+ messages in thread

* Re: [OE-core][scarthgap 00/11] Patch review
  2026-04-20  9:21   ` Yoann Congal
@ 2026-04-20 10:51     ` Joao Marcos Costa
  0 siblings, 0 replies; 25+ messages in thread
From: Joao Marcos Costa @ 2026-04-20 10:51 UTC (permalink / raw)
  To: openembedded-core

Hello,

On 4/20/26 11:21, Yoann Congal via lists.openembedded.org wrote:
> On Mon Apr 20, 2026 at 10:44 AM CEST, Joao Marcos Costa wrote:
>> Hello, Yoan
>>
>>
>> On 3/30/26 00:46, Yoann Congal via lists.openembedded.org wrote:
>>> Please review this set of changes for scarthgap and have comments back by
>>> end of day Tuesday, March 31.
>> (...)
>>
>> Was the commit below not picked, or am I missing something?
>>
>> commit b24d5cda19136fb8120154279eedd55d162b4640
>> Author: João Marcos Costa (Schneider Electric)
>> <joaomarcos.costa@bootlin.com>
>> Date:   Fri Apr 3 11:32:30 2026 +0200
>>
>>       linux-yocto/6.6: update CVE exclusions (6.6.123)
>>
>>       This new version of cve-exclusion_6.6.inc was generated with oe-core's
>>       latest version of the generate-cve-exclusions.py.
>>
>>       Regarding the database used and how this file was generated:
>>
>>       Generated at 2026-04-03 09:30:32.247568+00:00 for kernel version
>> 6.6.123
>>       From cvelistV5 cve_2026-04-03_0700Z
>>
>>       The backporting of the generate-cve-exclusions.py script from master to
>>       Scarthgap is handled in a different patch.
>>
>>       Signed-off-by: João Marcos Costa (Schneider Electric)
>> <joaomarcos.costa@bootlin.com>
>>
>> However, I see the commit below, prior to this one, was kept:
>>
>> linux/generate-cve-exclusions: backport script from master branch
>>
>> I'm not really used to the backports schedule/workflow, so please excuse
>> me if I misinterpreted something.
>>
>> Thanks!
> 
> This patch triggered a problem in our infra. I received it directly from
> you but it is missing from lore. And lore feeds patchwork, and I use
> patchwork to prepare my review branch...
> 
> This is a known problem: 16167 – Missing (big) patch in patchwork
> https://bugzilla.yoctoproject.org/show_bug.cgi?id=16167
> 
> I've reopened and added your patch to the bug log.
> 
> I will now integrate your patch in my review branch.
> 
> Thanks for the report, otherwise I would have missed it.
> 
> I'll try to check for this issue in the future but this will be hard to
> spot. If you send a similar patch in the future don't hesitate to ping
> me if you see it missing during the patch review period.
> 
> Regards,

Ack. Thanks!


-- 
Best regards,
João Marcos Costa


^ permalink raw reply	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 00/11] Patch review
@ 2026-08-25 10:06 Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 01/11] nghttp2: set status for CVE-2026-58055 Yoann Congal
                   ` (10 more replies)
  0 siblings, 11 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for scarthgap and have comments back by
end of day Thursday, August 27.

Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/29/builds/4569

The following changes since commit 70dc15941dd33270a92d1001174efb3093e79bdf:

  build-appliance-image: Update to scarthgap head revision (2026-08-24 14:28:47 +0100)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

for you to fetch changes up to b7007d82eec734bab6760ae325645ae5b199e384:

  rpcbind: Fix CVE-2026-16277 (2026-08-25 07:01:14 +0200)

----------------------------------------------------------------

Adarsh Jagadish Kamini (1):
  libssh2: fix CVE-2026-58050

Deepak Rathore (2):
  nghttp2: set status for CVE-2026-58055
  glib-2.0: fix CVE-2026-58015

Etienne Cordonnier (1):
  curl: fix CVE-2025-10148 backport for websockets on 8.7.1

Jaipaul Cheernam (4):
  binutils: fix CVE-2025-1147
  binutils: fix CVE-2025-8224
  binutils: fix CVE-2026-15003
  binutils: fix CVE-2026-18220

Peter Marko (1):
  bison: patch CVE-2026-56389

Ross Burton (1):
  bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES

Vijay Anusuri (1):
  rpcbind: Fix CVE-2026-16277

 meta/conf/bitbake.conf                        |   6 +-
 .../glib-2.0/glib-2.0/CVE-2026-58015_p1.patch |  97 +++++
 .../glib-2.0/glib-2.0/CVE-2026-58015_p2.patch |  55 +++
 .../glib-2.0/glib-2.0/CVE-2026-58015_p3.patch | 198 +++++++++
 .../glib-2.0/glib-2.0/CVE-2026-58015_p4.patch | 222 ++++++++++
 meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |   4 +
 meta/recipes-core/glib-2.0/glib.inc           |   2 +-
 .../binutils/binutils-2.42.inc                |   4 +
 .../binutils/binutils/CVE-2025-1147.patch     | 110 +++++
 .../binutils/binutils/CVE-2025-8224.patch     |  54 +++
 .../binutils/binutils/CVE-2026-15003.patch    | 400 ++++++++++++++++++
 .../binutils/binutils/CVE-2026-18220.patch    |  65 +++
 .../bison/bison/CVE-2026-56389.patch          |  56 +++
 meta/recipes-devtools/bison/bison_3.8.2.bb    |   1 +
 .../rpcbind/rpcbind/CVE-2026-16277.patch      |  34 ++
 .../recipes-extended/rpcbind/rpcbind_1.2.6.bb |   1 +
 .../curl/curl/CVE-2025-10148.patch            |  24 +-
 .../libssh2/libssh2/CVE-2026-58050.patch      |  45 ++
 .../recipes-support/libssh2/libssh2_1.11.1.bb |   1 +
 .../recipes-support/nghttp2/nghttp2_1.61.0.bb |   2 +
 20 files changed, 1367 insertions(+), 14 deletions(-)
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch
 create mode 100644 meta/recipes-devtools/bison/bison/CVE-2026-56389.patch
 create mode 100644 meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch
 create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch



^ permalink raw reply	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 01/11] nghttp2: set status for CVE-2026-58055
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 02/11] binutils: fix CVE-2025-1147 Yoann Congal
                   ` (9 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

CVE-2026-58055 affects the nghttpx proxy when forwarding HTTP/1.1
Upgrade requests with a Content-Length header and body.

The default recipe does not build nghttpx. Add a conditional
CVE_STATUS entry so the CVE remains unpatched if app support is
enabled, while default builds are marked not-applicable-config.

References:
https://nvd.nist.gov/vuln/detail/CVE-2026-58055

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 meta/recipes-support/nghttp2/nghttp2_1.61.0.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb b/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb
index ebba15db282..9ed27b72770 100644
--- a/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb
+++ b/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb
@@ -16,6 +16,8 @@ PACKAGECONFIG[manpages] = ""
 # first place
 EXTRA_OECMAKE = "-DENABLE_EXAMPLES=OFF -DENABLE_APP=OFF -DENABLE_HPACK_TOOLS=OFF -DENABLE_PYTHON_BINDINGS=OFF"
 
+CVE_STATUS[CVE-2026-58055] = "${@bb.utils.contains('EXTRA_OECMAKE', '-DENABLE_APP=OFF', 'not-applicable-config: nghttpx proxy is not built in the default nghttp2 configuration', 'unpatched', d)}"
+
 PACKAGES =+ "lib${BPN} ${PN}-proxy "
 
 RDEPENDS:${PN} = "${PN}-proxy (>= ${PV})"


^ permalink raw reply related	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 02/11] binutils: fix CVE-2025-1147
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 01/11] nghttp2: set status for CVE-2026-58055 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 03/11] binutils: fix CVE-2025-8224 Yoann Congal
                   ` (8 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-1147
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=7be4186c22f89a87fff048c28910f5d26a0f61ce

Test results:
  binutils-cross-testsuite 2.42 (x86_64-oe-linux):

  Before:
  binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

  After:
  binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported (+2 new passes from nm --ifunc-chars=-- tests)
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=7be4186c22f89a87fff048c28910f5d26a0f61ce]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 .../binutils/binutils-2.42.inc                |   1 +
 .../binutils/binutils/CVE-2025-1147.patch     | 110 ++++++++++++++++++
 2 files changed, 111 insertions(+)
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch

diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc
index d455acd7863..063c6cc2a43 100644
--- a/meta/recipes-devtools/binutils/binutils-2.42.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.42.inc
@@ -78,5 +78,6 @@ SRC_URI = "\
      file://CVE-2025-69652.patch \
      file://CVE-2026-6846.patch \
      file://CVE-2025-69645.patch \
+     file://CVE-2025-1147.patch \
 "
 S  = "${WORKDIR}/git"
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch
new file mode 100644
index 00000000000..9a95775d3f0
--- /dev/null
+++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch
@@ -0,0 +1,110 @@
+From 7be4186c22f89a87fff048c28910f5d26a0f61ce Mon Sep 17 00:00:00 2001
+From: Dmitry Klochkov <dmitry.klochkov@bell-sw.com>
+Date: Tue, 9 Sep 2025 12:06:25 +0200
+Subject: [PATCH] nm: fix treating an ifunc symbol as a stab if
+ '--ifunc-chars=--' is given
+
+If an ifunc symbol is processed in print_symbol(), a 'type' field of a
+'syminfo' structure is set to any character specified by a user with an
+'--ifunc-chars' option.  But afterwards the 'type' field is used to
+check whether a symbol is a stab in print_symbol_info_{bsd,sysv}()
+functions in order to print additional stab related data.  If the 'type'
+field equals '-', a symbol is treated as a stab.  If '--ifunc-chars=--'
+is given, all ifunc symbols will be treated as stab symbols and
+uninitialized stab related fields of the 'syminfo' structure will be
+printed which can lead to segmentation fault.
+
+To fix this, check if a symbol is a stab before override the 'type'
+field.  Also, add a test case for this fix.
+
+	PR binutils/32556
+	* nm.c (extended_symbol_info): Add is_stab.
+	(print_symbol): Check if a symbol is a stab.
+	(print_symbol_info_bsd): Use info->is_stab.
+	(print_symbol_info_sysv): Use info->is_stab.
+	* testsuite/binutils-all/nm.exp: Test nm --ifunc-chars=--.
+
+Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=32556
+Fixes: e6f6aa8d184 ("Add option to nm to change the characters displayed for ifunc symbols")
+Signed-off-by: Dmitry Klochkov <dmitry.klochkov@bell-sw.com>
+
+CVE: CVE-2025-1147
+Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=7be4186c22f89a87fff048c28910f5d26a0f61ce]
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ binutils/nm.c                          | 10 +++++++---
+ binutils/testsuite/binutils-all/nm.exp | 17 +++++++++++++++++
+ 2 files changed, 24 insertions(+), 3 deletions(-)
+
+diff --git a/binutils/nm.c b/binutils/nm.c
+index dce9207f44f..c3d118a93c3 100644
+--- a/binutils/nm.c
++++ b/binutils/nm.c
+@@ -70,6 +70,7 @@ struct extended_symbol_info
+   bfd_vma ssize;
+   elf_symbol_type *elfinfo;
+   coff_symbol_type *coffinfo;
++  bool is_stab;
+   /* FIXME: We should add more fields for Type, Line, Section.  */
+ };
+ #define SYM_VALUE(sym)       (sym->sinfo->value)
+@@ -1208,8 +1209,11 @@ print_symbol (bfd *        abfd,
+ 
+   bfd_get_symbol_info (abfd, sym, &syminfo);
+ 
++  info.is_stab = false;
++  if (syminfo.type == '-')
++    info.is_stab = true;
+   /* PR 22967 - Distinguish between local and global ifunc symbols.  */
+-  if (syminfo.type == 'i'
++  else if (syminfo.type == 'i'
+       && sym->flags & BSF_GNU_INDIRECT_FUNCTION)
+     {
+       if (ifunc_type_chars == NULL || ifunc_type_chars[0] == 0)
+@@ -1873,7 +1877,7 @@ print_symbol_info_bsd (struct extended_symbol_info *info, bfd *abfd)
+ 
+   printf (" %c", SYM_TYPE (info));
+ 
+-  if (SYM_TYPE (info) == '-')
++  if (info->is_stab)
+     {
+       /* A stab.  */
+       printf (" ");
+@@ -1902,7 +1906,7 @@ print_symbol_info_sysv (struct extended_symbol_info *info, bfd *abfd)
+ 
+   printf ("|   %c  |", SYM_TYPE (info));
+ 
+-  if (SYM_TYPE (info) == '-')
++  if (info->is_stab)
+     {
+       /* A stab.  */
+       printf ("%18s|  ", SYM_STAB_NAME (info));		/* (C) Type.  */
+diff --git a/binutils/testsuite/binutils-all/nm.exp b/binutils/testsuite/binutils-all/nm.exp
+index fea68bf76bc..1feb8578fba 100644
+--- a/binutils/testsuite/binutils-all/nm.exp
++++ b/binutils/testsuite/binutils-all/nm.exp
+@@ -329,6 +329,23 @@ if [is_elf_format] {
+ 	    fail "$testname (local ifunc)"
+ 	}
+ 
++	# PR 32556
++	# Test nm --ifunc-chars=--
++
++	set got [binutils_run $NM "$NMFLAGS --ifunc-chars=-- $tmpfile"]
++
++	if [regexp -line "^\\S+ - global_foo$" $got] then {
++	    pass "$testname=-- (global ifunc)"
++	} else {
++	    fail "$testname=-- (global ifunc)"
++	}
++
++	if [regexp -line "^\\S+ - local_foo$" $got] then {
++	    pass "$testname=-- (local ifunc)"
++	} else {
++	    fail "$testname=-- (local ifunc)"
++	}
++
+ 	if { $verbose < 1 } {
+ 	    remote_file host delete "tmpdir/ifunc.o"
+ 	}


^ permalink raw reply related	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 03/11] binutils: fix CVE-2025-8224
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 01/11] nghttp2: set status for CVE-2026-58055 Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 02/11] binutils: fix CVE-2025-1147 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 04/11] binutils: fix CVE-2026-15003 Yoann Congal
                   ` (7 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-8224
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=db856d41004301b3a56438efd957ef5cabb91530

[Adapted for binutils 2.42: only the shstrtabsize overflow check in
bfd_elf_get_str_section applies. The second upstream hunk (DT_STRTAB)
does not apply as 2.42 already unconditionally null-terminates the
dynamic string table.]

Test results:
  binutils-cross-testsuite 2.42 (x86_64-oe-linux):

  Before:
  binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

  After:
  binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=db856d41004301b3a56438efd957ef5cabb91530]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 .../binutils/binutils-2.42.inc                |  1 +
 .../binutils/binutils/CVE-2025-8224.patch     | 54 +++++++++++++++++++
 2 files changed, 55 insertions(+)
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch

diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc
index 063c6cc2a43..5534ce577f9 100644
--- a/meta/recipes-devtools/binutils/binutils-2.42.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.42.inc
@@ -79,5 +79,6 @@ SRC_URI = "\
      file://CVE-2026-6846.patch \
      file://CVE-2025-69645.patch \
      file://CVE-2025-1147.patch \
+     file://CVE-2025-8224.patch \
 "
 S  = "${WORKDIR}/git"
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch
new file mode 100644
index 00000000000..914b9084c27
--- /dev/null
+++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch
@@ -0,0 +1,54 @@
+From db856d41004301b3a56438efd957ef5cabb91530 Mon Sep 17 00:00:00 2001
+From: Alan Modra <amodra@gmail.com>
+Date: Sun, 25 Aug 2024 15:20:21 +0930
+Subject: [PATCH] PR32109, aborting at bfd/bfd.c:1236 in int _bfd_doprnt
+
+Since bfd_section for .strtab isn't set, print the section index
+instead.  Also, don't return NULL on this error as that results in
+multiple mmap/read of the string table.  (We could return NULL if we
+arranged to set sh_size zero first, but just what we do with fuzzed
+object files is of no concern, and terminating the table might make a
+faulty object file usable.)
+
+	PR 32109
+	* elf.c (bfd_elf_get_str_section): Remove outdated comment, and
+	tweak shstrtabsize test to suit.  Don't use string tab bfd_section
+	in error message, use index instead.  Don't return NULL on
+	unterminated string section, terminate it.
+	(_bfd_elf_get_dynamic_symbols): Similarly terminate string table
+	section.
+
+[Backport note: Adapted for binutils 2.42. The upstream commit targets
+a newer codebase that uses _bfd_mmap_readonly_persistent and has an
+explicit unterminated-string error path with return NULL. In 2.42 the
+code uses _bfd_alloc_and_read with shstrtabsize+1 allocation and
+unconditionally null-terminates via shstrtab[shstrtabsize] = '\0'.
+Only the shstrtabsize overflow check fix applies here (shstrtabsize + 1 <= 1
+changed to shstrtabsize == 0). The second upstream hunk (DT_STRTAB
+error_return -> terminate) does not apply as 2.42 already
+unconditionally null-terminates the dynamic string table.]
+
+CVE: CVE-2025-8224
+Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=db856d41004301b3a56438efd957ef5cabb91530]
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ bfd/elf.c | 4 +---
+ 1 file changed, 1 insertion(+), 3 deletions(-)
+
+diff --git a/bfd/elf.c b/bfd/elf.c
+--- a/bfd/elf.c
++++ b/bfd/elf.c
+@@ -285,9 +285,7 @@ bfd_elf_get_str_section (bfd *abfd, unsigned int shindex)
+       offset = i_shdrp[shindex]->sh_offset;
+       shstrtabsize = i_shdrp[shindex]->sh_size;
+ 
+-      /* Allocate and clear an extra byte at the end, to prevent crashes
+-	 in case the string table is not terminated.  */
+-      if (shstrtabsize + 1 <= 1
++      if (shstrtabsize == 0
+ 	  || bfd_seek (abfd, offset, SEEK_SET) != 0
+ 	  || (shstrtab = _bfd_alloc_and_read (abfd, shstrtabsize + 1,
+ 					      shstrtabsize)) == NULL)
+-- 
+2.43.7


^ permalink raw reply related	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 04/11] binutils: fix CVE-2026-15003
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
                   ` (2 preceding siblings ...)
  2026-08-25 10:06 ` [OE-core][scarthgap 03/11] binutils: fix CVE-2025-8224 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 05/11] binutils: fix CVE-2026-18220 Yoann Congal
                   ` (6 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-15003
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c

Test results:
  binutils-cross-testsuite 2.42 (x86_64-oe-linux):

  Before:
  binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

  After:
  binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 .../binutils/binutils-2.42.inc                |   1 +
 .../binutils/binutils/CVE-2026-15003.patch    | 400 ++++++++++++++++++
 2 files changed, 401 insertions(+)
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch

diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc
index 5534ce577f9..447529ffa95 100644
--- a/meta/recipes-devtools/binutils/binutils-2.42.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.42.inc
@@ -80,5 +80,6 @@ SRC_URI = "\
      file://CVE-2025-69645.patch \
      file://CVE-2025-1147.patch \
      file://CVE-2025-8224.patch \
+     file://CVE-2026-15003.patch \
 "
 S  = "${WORKDIR}/git"
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch b/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch
new file mode 100644
index 00000000000..2f5c42e1b93
--- /dev/null
+++ b/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch
@@ -0,0 +1,400 @@
+From 23acf2f003f81b2f8d9d1997ea45d822d33d386c Mon Sep 17 00:00:00 2001
+From: Alan Modra <amodra@gmail.com>
+Date: Thu, 9 Apr 2026 09:06:27 +0930
+Subject: [PATCH] PR 34053 buffer overflow in xcoff_link_add_symbols
+
+This patch adds two sanity checks with error reporting in
+xcoff_link_add_symbols before reading symbol aux entries, add extends
+assertions in later functions.  A whole lot of unnecessary casts are
+also tidied.
+
+	PR 34053
+	* xcofflink.c: Remove unnecessary casts throughout.
+	(xcoff_link_add_symbols): Sanity check aux entries are within
+	symbol buffer.
+	(bfd_xcoff_build_dynamic_sections): Assert the above is true.
+	(xcoff_link_input_bfd): Likewise.
+
+CVE: CVE-2026-15003
+Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c]
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ bfd/xcofflink.c | 132 +++++++++++++++++++++++-------------------------
+ 1 file changed, 62 insertions(+), 70 deletions(-)
+
+diff --git a/bfd/xcofflink.c b/bfd/xcofflink.c
+index 7f1c0df760f..cf3b33e7202 100644
+--- a/bfd/xcofflink.c
++++ b/bfd/xcofflink.c
+@@ -371,7 +371,7 @@ _bfd_xcoff_canonicalize_dynamic_symtab (bfd *abfd, asymbol **psyms)
+ 	{
+ 	  char *c;
+ 
+-	  c = bfd_alloc (abfd, (bfd_size_type) SYMNMLEN + 1);
++	  c = bfd_alloc (abfd, SYMNMLEN + 1);
+ 	  if (c == NULL)
+ 	    return -1;
+ 	  memcpy (c, ldsym._l._l_name, SYMNMLEN);
+@@ -1038,7 +1038,7 @@ xcoff_link_add_dynamic_symbols (bfd *abfd, struct bfd_link_info *info)
+ 	    {
+ 	      char *dsnm;
+ 
+-	      dsnm = bfd_malloc ((bfd_size_type) strlen (name) + 2);
++	      dsnm = bfd_malloc (strlen (name) + 2);
+ 	      if (dsnm == NULL)
+ 		return false;
+ 	      dsnm[0] = '.';
+@@ -1081,7 +1081,7 @@ xcoff_link_add_dynamic_symbols (bfd *abfd, struct bfd_link_info *info)
+   coff_section_data (abfd, lsec)->contents = NULL;
+ 
+   /* Record this file in the import files.  */
+-  n = bfd_alloc (abfd, (bfd_size_type) sizeof (struct xcoff_import_file));
++  n = bfd_alloc (abfd, sizeof (*n));
+   if (n == NULL)
+     return false;
+   n->next = NULL;
+@@ -1477,7 +1477,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+       bfd_vma value;
+       struct xcoff_link_hash_entry *set_toc;
+ 
+-      bfd_coff_swap_sym_in (abfd, (void *) esym, (void *) &sym);
++      bfd_coff_swap_sym_in (abfd, esym, &sym);
+ 
+       /* In this pass we are only interested in symbols with csect
+ 	 information.  */
+@@ -1523,9 +1523,12 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+ 	{
+ 	  union internal_auxent auxlin;
+ 
+-	  bfd_coff_swap_aux_in (abfd, (void *) (esym + symesz),
++	  if (symesz >= (size_t) (esym_end - esym))
++	    goto badaux;
++
++	  bfd_coff_swap_aux_in (abfd, esym + symesz,
+ 				sym.n_type, sym.n_sclass,
+-				0, sym.n_numaux, (void *) &auxlin);
++				0, sym.n_numaux, &auxlin);
+ 
+ 	  if (auxlin.x_sym.x_fcnary.x_fcn.x_lnnoptr != 0)
+ 	    {
+@@ -1552,7 +1555,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+ 
+ 		  linpstart = (reloc_info[enclosing->target_index].linenos
+ 			       + linoff);
+-		  bfd_coff_swap_lineno_in (abfd, (void *) linpstart, (void *) &lin);
++		  bfd_coff_swap_lineno_in (abfd, linpstart, &lin);
+ 		  if (lin.l_lnno == 0
+ 		      && ((bfd_size_type) lin.l_addr.l_symndx
+ 			  == ((esym
+@@ -1567,8 +1570,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+ 			   linp < linpend;
+ 			   linp += linesz)
+ 			{
+-			  bfd_coff_swap_lineno_in (abfd, (void *) linp,
+-						   (void *) &lin);
++			  bfd_coff_swap_lineno_in (abfd, linp, &lin);
+ 			  if (lin.l_lnno == 0)
+ 			    break;
+ 			}
+@@ -1589,21 +1591,21 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+       visibility = sym.n_type & SYM_V_MASK;
+ 
+       /* Pick up the csect auxiliary information.  */
+-      if (sym.n_numaux == 0)
++      if (sym.n_numaux < 1
++	  || sym.n_numaux * symesz >= (size_t) (esym_end - esym))
+ 	{
++	badaux:
+ 	  _bfd_error_handler
+ 	    /* xgettext:c-format */
+-	    (_("%pB: class %d symbol `%s' has no aux entries"),
++	    (_("%pB: class %d symbol '%s' has missing aux entries"),
+ 	     abfd, sym.n_sclass, name);
+ 	  bfd_set_error (bfd_error_bad_value);
+ 	  goto error_return;
+ 	}
+ 
+-      bfd_coff_swap_aux_in (abfd,
+-			    (void *) (esym + symesz * sym.n_numaux),
++      bfd_coff_swap_aux_in (abfd, esym + symesz * sym.n_numaux,
+ 			    sym.n_type, sym.n_sclass,
+-			    sym.n_numaux - 1, sym.n_numaux,
+-			    (void *) &aux);
++			    sym.n_numaux - 1, sym.n_numaux, &aux);
+ 
+       smtyp = SMTYP_SMTYP (aux.x_csect.x_smtyp);
+ 
+@@ -1726,7 +1728,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+ 
+ 		  erelsym = ((bfd_byte *) obj_coff_external_syms (abfd)
+ 			     + rel->r_symndx * symesz);
+-		  bfd_coff_swap_sym_in (abfd, (void *) erelsym, (void *) &relsym);
++		  bfd_coff_swap_sym_in (abfd, erelsym, &relsym);
+ 		  if (EXTERN_SYM_P (relsym.n_sclass))
+ 		    {
+ 		      const char *relname;
+@@ -2507,7 +2509,7 @@ xcoff_link_check_ar_symbols (bfd *abfd,
+     {
+       struct internal_syment sym;
+ 
+-      bfd_coff_swap_sym_in (abfd, (void *) esym, (void *) &sym);
++      bfd_coff_swap_sym_in (abfd, esym, &sym);
+       esym += (sym.n_numaux + 1) * symesz;
+ 
+       if (EXTERN_SYM_P (sym.n_sclass) && sym.n_scnum != N_UNDEF)
+@@ -4005,7 +4007,7 @@ bfd_xcoff_size_dynamic_sections (bfd *output_bfd,
+     return true;
+ 
+   xcoff_link_hash_traverse (xcoff_hash_table (info), xcoff_post_gc_symbol,
+-			    (void *) ldinfo);
++			    ldinfo);
+   if (ldinfo->failed)
+     goto error_return;
+ 
+@@ -4216,7 +4218,8 @@ bfd_xcoff_build_dynamic_sections (bfd *output_bfd,
+ 	  /* Read in the csect information, if any.  */
+ 	  if (CSECT_SYM_P (sym.n_sclass))
+ 	    {
+-	      BFD_ASSERT (sym.n_numaux > 0);
++	      BFD_ASSERT (sym.n_numaux > 0
++			  && symesz * sym.n_numaux < (size_t) (esymend - esym));
+ 	      bfd_coff_swap_aux_in (sub, esym + symesz * sym.n_numaux,
+ 				    sym.n_type, sym.n_sclass,
+ 				    sym.n_numaux - 1, sym.n_numaux, &aux);
+@@ -4307,7 +4310,7 @@ bfd_xcoff_link_generate_rtinit (bfd *abfd,
+ {
+   struct bfd_in_memory *bim;
+ 
+-  bim = bfd_malloc ((bfd_size_type) sizeof (* bim));
++  bim = bfd_malloc (sizeof (*bim));
+   if (bim == NULL)
+     return false;
+ 
+@@ -4316,7 +4319,7 @@ bfd_xcoff_link_generate_rtinit (bfd *abfd,
+ 
+   abfd->link.next = 0;
+   abfd->format = bfd_object;
+-  abfd->iostream = (void *) bim;
++  abfd->iostream = bim;
+   abfd->flags = BFD_IN_MEMORY;
+   abfd->iovec = &_bfd_memory_iovec;
+   abfd->direction = write_direction;
+@@ -4876,8 +4879,8 @@ bfd_xcoff_size_stubs (struct bfd_link_info *info)
+ 			}
+ 
+ 		      bfd_coff_swap_sym_in (input_bfd,
+-					    (void *) esyms + irel->r_symndx * symesz,
+-					    (void *) &sym);
++					    esyms + irel->r_symndx * symesz,
++					    &sym);
+ 
+ 		      sym_sec = xcoff_data (input_bfd)->csects[irel->r_symndx];
+ 		      sym_value = sym.n_value - sym_sec->vma;
+@@ -5250,17 +5253,16 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+       int smtyp = 0;
+       int add;
+ 
+-      bfd_coff_swap_sym_in (input_bfd, (void *) esym, (void *) isymp);
++      bfd_coff_swap_sym_in (input_bfd, esym, isymp);
+ 
+       /* Read in the csect information, if any.  */
+       if (CSECT_SYM_P (isymp->n_sclass))
+ 	{
+-	  BFD_ASSERT (isymp->n_numaux > 0);
+-	  bfd_coff_swap_aux_in (input_bfd,
+-				(void *) (esym + isymesz * isymp->n_numaux),
++	  BFD_ASSERT (isymp->n_numaux > 0
++		      && isymesz * isymp->n_numaux < (size_t) (esym_end - esym));
++	  bfd_coff_swap_aux_in (input_bfd, esym + isymesz * isymp->n_numaux,
+ 				isymp->n_type, isymp->n_sclass,
+-				isymp->n_numaux - 1, isymp->n_numaux,
+-				(void *) &aux);
++				isymp->n_numaux - 1, isymp->n_numaux, &aux);
+ 
+ 	  smtyp = SMTYP_SMTYP (aux.x_csect.x_smtyp);
+ 	}
+@@ -5475,12 +5477,10 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ 		  if ((bfd_size_type) flinfo->last_file_index >= syment_base)
+ 		    {
+ 		      /* The last C_FILE symbol is in this input file.  */
+-		      bfd_coff_swap_sym_out (output_bfd,
+-					     (void *) &flinfo->last_file,
+-					     (void *) (flinfo->outsyms
+-						    + ((flinfo->last_file_index
+-							- syment_base)
+-						       * osymesz)));
++		      bfd_coff_swap_sym_out
++			(output_bfd, &flinfo->last_file,
++			 flinfo->outsyms + (flinfo->last_file_index
++					    - syment_base) * osymesz);
+ 		    }
+ 		  else
+ 		    {
+@@ -5489,9 +5489,8 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ 			 borrow *outsym temporarily.  */
+ 		      file_ptr pos;
+ 
+-		      bfd_coff_swap_sym_out (output_bfd,
+-					     (void *) &flinfo->last_file,
+-					     (void *) outsym);
++		      bfd_coff_swap_sym_out (output_bfd, &flinfo->last_file,
++					     outsym);
+ 
+ 		      pos = obj_sym_filepos (output_bfd);
+ 		      pos += flinfo->last_file_index * osymesz;
+@@ -5557,7 +5556,7 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ 	    }
+ 
+ 	  /* Output the symbol.  */
+-	  bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym);
++	  bfd_coff_swap_sym_out (output_bfd, &isym, outsym);
+ 
+ 	  esym += isymesz;
+ 	  outsym += osymesz;
+@@ -5566,9 +5565,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ 	    {
+ 	      union internal_auxent aux;
+ 
+-	      bfd_coff_swap_aux_in (input_bfd, (void *) esym, isymp->n_type,
+-				    isymp->n_sclass, i, isymp->n_numaux,
+-				    (void *) &aux);
++	      bfd_coff_swap_aux_in (input_bfd, esym,
++				    isymp->n_type, isymp->n_sclass, i,
++				    isymp->n_numaux, &aux);
+ 
+ 	      if (isymp->n_sclass == C_FILE)
+ 		{
+@@ -5796,9 +5795,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ 		    }
+ 		}
+ 
+-	      bfd_coff_swap_aux_out (output_bfd, (void *) &aux, isymp->n_type,
++	      bfd_coff_swap_aux_out (output_bfd, &aux, isymp->n_type,
+ 				     isymp->n_sclass, i, isymp->n_numaux,
+-				     (void *) outsym);
++				     outsym);
+ 	      outsym += osymesz;
+ 	      esym += isymesz;
+ 	    }
+@@ -5820,10 +5819,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+       && (bfd_size_type) flinfo->last_file_index >= syment_base)
+     {
+       flinfo->last_file.n_value = output_index;
+-      bfd_coff_swap_sym_out (output_bfd, (void *) &flinfo->last_file,
+-			     (void *) (flinfo->outsyms
+-				    + ((flinfo->last_file_index - syment_base)
+-				       * osymesz)));
++      bfd_coff_swap_sym_out (output_bfd, &flinfo->last_file,
++			     flinfo->outsyms + (flinfo->last_file_index
++						- syment_base) * osymesz);
+     }
+ 
+   /* Write the modified symbols to the output file.  */
+@@ -6036,16 +6034,13 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ 			      void * auxptr;
+ 			      union internal_auxent aux;
+ 
+-			      auxptr = ((void *)
+-					(((bfd_byte *)
+-					  obj_coff_external_syms (input_bfd))
+-					 + ((r_symndx + is->n_numaux)
+-					    * isymesz)));
++			      auxptr = ((bfd_byte *)
++					obj_coff_external_syms (input_bfd)
++					+ (r_symndx + is->n_numaux) * isymesz);
+ 			      bfd_coff_swap_aux_in (input_bfd, auxptr,
+ 						    is->n_type, is->n_sclass,
+ 						    is->n_numaux - 1,
+-						    is->n_numaux,
+-						    (void *) &aux);
++						    is->n_numaux, &aux);
+ 			      if (SMTYP_SMTYP (aux.x_csect.x_smtyp) == XTY_SD
+ 				  && aux.x_csect.x_smclas == XMC_TC0)
+ 				indx = flinfo->toc_symindx;
+@@ -6564,12 +6559,12 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf)
+ 	  irsym.n_type = T_NULL;
+ 	  irsym.n_numaux = 1;
+ 
+-	  bfd_coff_swap_sym_out (output_bfd, (void *) &irsym, (void *) outsym);
++	  bfd_coff_swap_sym_out (output_bfd, &irsym, outsym);
+ 	  outsym += bfd_coff_symesz (output_bfd);
+ 
+ 	  /* Note : iraux is initialized above.  */
+-	  bfd_coff_swap_aux_out (output_bfd, (void *) &iraux, T_NULL, C_HIDEXT,
+-				 0, 1, (void *) outsym);
++	  bfd_coff_swap_aux_out (output_bfd, &iraux, T_NULL, C_HIDEXT,
++				 0, 1, outsym);
+ 	  outsym += bfd_coff_auxesz (output_bfd);
+ 
+ 	  if (h->indx >= 0)
+@@ -6807,12 +6802,11 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf)
+   isym.n_type = T_NULL;
+   isym.n_numaux = 1;
+ 
+-  bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym);
++  bfd_coff_swap_sym_out (output_bfd, &isym, outsym);
+   outsym += bfd_coff_symesz (output_bfd);
+ 
+   aux.x_csect.x_smclas = h->smclas;
+-  bfd_coff_swap_aux_out (output_bfd, (void *) &aux, T_NULL, isym.n_sclass, 0, 1,
+-			 (void *) outsym);
++  bfd_coff_swap_aux_out (output_bfd, &aux, T_NULL, isym.n_sclass, 0, 1, outsym);
+   outsym += bfd_coff_auxesz (output_bfd);
+ 
+   if ((h->root.type == bfd_link_hash_defined
+@@ -6827,13 +6821,12 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf)
+ 	isym.n_sclass = C_WEAKEXT;
+       else
+ 	isym.n_sclass = C_EXT;
+-      bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym);
++      bfd_coff_swap_sym_out (output_bfd, &isym, outsym);
+       outsym += bfd_coff_symesz (output_bfd);
+ 
+       aux.x_csect.x_smtyp = XTY_LD;
+       aux.x_csect.x_scnlen.u64 = obj_raw_syment_count (output_bfd);
+-      bfd_coff_swap_aux_out (output_bfd, (void *) &aux, T_NULL, C_EXT, 0, 1,
+-			     (void *) outsym);
++      bfd_coff_swap_aux_out (output_bfd, &aux, T_NULL, C_EXT, 0, 1, outsym);
+       outsym += bfd_coff_auxesz (output_bfd);
+     }
+ 
+@@ -6929,8 +6922,8 @@ xcoff_reloc_link_order (bfd *output_bfd,
+ 	     howto->name, addend, NULL, NULL, (bfd_vma) 0);
+ 	  break;
+ 	}
+-      ok = bfd_set_section_contents (output_bfd, output_section, (void *) buf,
+-				     (file_ptr) link_order->offset, size);
++      ok = bfd_set_section_contents (output_bfd, output_section, buf,
++				     link_order->offset, size);
+       free (buf);
+       if (! ok)
+ 	return false;
+@@ -7395,8 +7388,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info)
+   if (flinfo.last_file_index != -1)
+     {
+       flinfo.last_file.n_value = -(bfd_vma) 1;
+-      bfd_coff_swap_sym_out (abfd, (void *) &flinfo.last_file,
+-			     (void *) flinfo.outsyms);
++      bfd_coff_swap_sym_out (abfd, &flinfo.last_file, flinfo.outsyms);
+       pos = obj_sym_filepos (abfd) + flinfo.last_file_index * symesz;
+       if (bfd_seek (abfd, pos, SEEK_SET) != 0
+ 	  || bfd_write (flinfo.outsyms, symesz, abfd) != symesz)
+@@ -7480,7 +7472,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info)
+ 	 appear in the symbol table, which is not necessarily by
+ 	 address.  So we sort them here.  There may be a better way to
+ 	 do this.  */
+-      qsort ((void *) flinfo.section_info[o->target_index].relocs,
++      qsort (flinfo.section_info[o->target_index].relocs,
+ 	     o->reloc_count, sizeof (struct internal_reloc),
+ 	     xcoff_sort_relocs);
+ 
+@@ -7488,7 +7480,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info)
+       irelend = irel + o->reloc_count;
+       erel = external_relocs;
+       for (; irel < irelend; irel++, rel_hash++, erel += relsz)
+-	bfd_coff_swap_reloc_out (abfd, (void *) irel, (void *) erel);
++	bfd_coff_swap_reloc_out (abfd, irel, erel);
+ 
+       rel_size = relsz * o->reloc_count;
+       if (bfd_seek (abfd, o->rel_filepos, SEEK_SET) != 0


^ permalink raw reply related	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 05/11] binutils: fix CVE-2026-18220
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
                   ` (3 preceding siblings ...)
  2026-08-25 10:06 ` [OE-core][scarthgap 04/11] binutils: fix CVE-2026-15003 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 06/11] libssh2: fix CVE-2026-58050 Yoann Congal
                   ` (5 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-18220
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=114e3aae2b7e34057c8909301eaf78c15687e8e5

Test results:
  binutils-cross-testsuite 2.42 (x86_64-oe-linux):

  Before:
  binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

  After:
  binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=114e3aae2b7e34057c8909301eaf78c15687e8e5]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 .../binutils/binutils-2.42.inc                |  1 +
 .../binutils/binutils/CVE-2026-18220.patch    | 65 +++++++++++++++++++
 2 files changed, 66 insertions(+)
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch

diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc
index 447529ffa95..d395ae1b1e0 100644
--- a/meta/recipes-devtools/binutils/binutils-2.42.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.42.inc
@@ -81,5 +81,6 @@ SRC_URI = "\
      file://CVE-2025-1147.patch \
      file://CVE-2025-8224.patch \
      file://CVE-2026-15003.patch \
+     file://CVE-2026-18220.patch \
 "
 S  = "${WORKDIR}/git"
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch b/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch
new file mode 100644
index 00000000000..e915fb223a1
--- /dev/null
+++ b/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch
@@ -0,0 +1,65 @@
+From 114e3aae2b7e34057c8909301eaf78c15687e8e5 Mon Sep 17 00:00:00 2001
+From: Alan Modra <amodra@gmail.com>
+Date: Sun, 28 Jun 2026 09:11:46 +0930
+Subject: [PATCH] asan: buffer overflow in elf32_dlx_relocate26
+
+	* elf32-dlx.c (elf32_dlx_relocate26): Sanity check reloc offset.
+	(elf32_dlx_relocate16): Likewise.
+	(_bfd_dlx_elf_hi16_reloc): Likewise, and remove ineffective
+	existing check.
+
+CVE: CVE-2026-18220
+Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=114e3aae2b7e34057c8909301eaf78c15687e8e5]
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ bfd/elf32-dlx.c | 15 ++++++++++++---
+ 1 file changed, 12 insertions(+), 3 deletions(-)
+
+diff --git a/bfd/elf32-dlx.c b/bfd/elf32-dlx.c
+index 2dfeb4d7390..0f9a49695d7 100644
+--- a/bfd/elf32-dlx.c
++++ b/bfd/elf32-dlx.c
+@@ -77,6 +77,10 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd,
+       return bfd_reloc_ok;
+     }
+ 
++  if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd,
++				  input_section, reloc_entry->address))
++    return bfd_reloc_outofrange;
++
+   ret = bfd_reloc_ok;
+ 
+   if (bfd_is_und_section (symbol->section)
+@@ -89,9 +93,6 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd,
+   relocation += reloc_entry->addend;
+   relocation += bfd_get_16 (abfd, (bfd_byte *)data + reloc_entry->address);
+ 
+-  if (reloc_entry->address > bfd_get_section_limit (abfd, input_section))
+-    return bfd_reloc_outofrange;
+-
+   bfd_put_16 (abfd, (short)((relocation >> 16) & 0xFFFF),
+ 	      (bfd_byte *)data + reloc_entry->address);
+ 
+@@ -143,6 +144,10 @@ elf32_dlx_relocate16 (bfd *abfd,
+       return bfd_reloc_undefined;
+     }
+ 
++  if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd,
++				  input_section, reloc_entry->address))
++    return bfd_reloc_outofrange;
++
+   insn  = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address);
+   allignment = 1 << (input_section->output_section->alignment_power - 1);
+   vallo = insn & 0x0000FFFF;
+@@ -206,6 +211,10 @@ elf32_dlx_relocate26 (bfd *abfd,
+       return bfd_reloc_undefined;
+     }
+ 
++  if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd,
++				  input_section, reloc_entry->address))
++    return bfd_reloc_outofrange;
++
+   insn  = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address);
+   allignment = 1 << (input_section->output_section->alignment_power - 1);
+   vallo = insn & 0x03FFFFFF;


^ permalink raw reply related	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 06/11] libssh2: fix CVE-2026-58050
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
                   ` (4 preceding siblings ...)
  2026-08-25 10:06 ` [OE-core][scarthgap 05/11] binutils: fix CVE-2026-18220 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 07/11] glib-2.0: fix CVE-2026-58015 Yoann Congal
                   ` (4 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>

Backport patch to fix CVE-2026-58050.

References:
  https://nvd.nist.gov/vuln/detail/CVE-2026-58050

Upstream fix:
  https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12

Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 .../libssh2/libssh2/CVE-2026-58050.patch      | 45 +++++++++++++++++++
 .../recipes-support/libssh2/libssh2_1.11.1.bb |  1 +
 2 files changed, 46 insertions(+)
 create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch

diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch
new file mode 100644
index 00000000000..0163b379f35
--- /dev/null
+++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch
@@ -0,0 +1,45 @@
+From 05b2fb4ec89d75235dbd97c5965dc0e46b405a7c Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <commit@vsz.me>
+Date: Sun, 28 Jun 2026 02:12:52 +0200
+Subject: [PATCH] publickey: fix potential multiplication overflow in 32-bit
+ `libssh2_publickey_list_fetch()`
+
+Cap list size at 1024 elements.
+
+Reported-and-initial-patch-by: Mateusz Gierblinski
+Reported-and-initial-patch-by: Behzod Abdullayev
+Reported-by: Sharique Raza
+
+Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9
+
+Closes #2128
+
+src/publickey.c: replaced ssh2_err() with _libssh2_error() to match
+the stable branch's error-reporting convention.
+
+Assisted-by: kiro:claude-sonnet-5
+
+CVE: CVE-2026-58050
+Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12]
+
+Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
+---
+ src/publickey.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/src/publickey.c b/src/publickey.c
+index 9c9fa618..196d2f9f 100644
+--- a/src/publickey.c
++++ b/src/publickey.c
+@@ -1114,6 +1114,11 @@ libssh2_publickey_list_fetch(LIBSSH2_PUBLICKEY * pkey, unsigned long *num_keys,
+                 }
+ 
+                 if(list[keys].num_attrs) {
++                    if(list[keys].num_attrs > 1024) {
++                        _libssh2_error(session, LIBSSH2_ERROR_OUT_OF_BOUNDARY,
++                                       "Too many publickey attributes");
++                        goto err_exit;
++                    }
+                     list[keys].attrs =
+                         LIBSSH2_ALLOC(session,
+                                       list[keys].num_attrs *
diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
index d14a27f3dc3..d3f39050474 100644
--- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb
+++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
@@ -20,6 +20,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \
            file://CVE-2026-66033.patch \
            file://CVE-2026-66034.patch \
            file://CVE-2026-66035.patch \
+           file://CVE-2026-58050.patch \
            "
 
 SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7"


^ permalink raw reply related	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 07/11] glib-2.0: fix CVE-2026-58015
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
                   ` (5 preceding siblings ...)
  2026-08-25 10:06 ` [OE-core][scarthgap 06/11] libssh2: fix CVE-2026-58050 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 08/11] curl: fix CVE-2025-10148 backport for websockets on 8.7.1 Yoann Congal
                   ` (3 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Deepak Rathore <deeratho@cisco.com>

This patch applies the upstream glib-2-88 stable backport chain for
CVE-2026-58015. The issue is in the D-Bus SHA-1 authentication
mechanism, where a malicious peer could provide an unchecked cookie
context and cause the client to access unintended files while resolving
the cookie challenge.

Backport the upstream GLib fix chain from the glib-2-88 stable branch:
- db9c8fae398b validates cookie_context before keyring lookup. This is
the primary security fix for CVE-2026-58015 [1].
- c0531125344b tightens cookie ID parsing so empty, negative, and
out-of-range values are rejected. This hardens the same SHA-1 cookie
challenge parser and is covered by the upstream regression test [2].
- 060aea67de75 exposes the private client reject-reason vfunc. This is
test-support plumbing required by the upstream regression test [3].
- 091930196229 adds the upstream regression test for SHA-1 cookie
challenge parsing [4].

Add dbus-native to PACKAGECONFIG[tests] so Meson can find dbus-daemon
when building the new installed D-Bus regression test for ptest. This is
kept as a native-only test dependency to avoid adding a target dbus
dependency to glib.

[1] https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a
[2] https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb
[3] https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22
[4] https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-58015

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 .../glib-2.0/glib-2.0/CVE-2026-58015_p1.patch |  97 ++++++++
 .../glib-2.0/glib-2.0/CVE-2026-58015_p2.patch |  55 +++++
 .../glib-2.0/glib-2.0/CVE-2026-58015_p3.patch | 198 ++++++++++++++++
 .../glib-2.0/glib-2.0/CVE-2026-58015_p4.patch | 222 ++++++++++++++++++
 meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |   4 +
 meta/recipes-core/glib-2.0/glib.inc           |   2 +-
 6 files changed, 577 insertions(+), 1 deletion(-)
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch

diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
new file mode 100644
index 00000000000..1216e1a12b1
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
@@ -0,0 +1,97 @@
+From 1d0d0dc891399e8572a6c96b116149d076e2de28 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:47:30 +0100
+Subject: [PATCH 1/4] gdbusauthmechanismsha1: Validate cookie context
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Without validation, the server could send a malicious context which
+contains path traversal characters, allowing it to exfiltrate a SHA-1
+hashed copy of arbitrary data from the client’s file system.
+
+To exploit this successfully would require the client to choose to
+connect peer-to-peer to a malicious D-Bus server and to choose the SHA-1
+authentication mechanism in preference to all the other mechanisms. This
+is vanishingly unlikely.
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a]
+
+Backport Changes:
+- Added <stdint.h> include because the target branch does not otherwise
+  expose uint8_t used by the upstream validation code during native builds.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+
+Fixes: #3931
+(cherry picked from commit db9c8fae398b0c457e660ce63dd5afec8993046a)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/gdbusauthmechanismsha1.c | 37 ++++++++++++++++++++++++++++++++++++
+ 1 file changed, 37 insertions(+)
+
+diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
+index c8aa08977..7d8fc1922 100644
+--- a/gio/gdbusauthmechanismsha1.c
++++ b/gio/gdbusauthmechanismsha1.c
+@@ -22,6 +22,7 @@
+ 
+ #include "config.h"
+ 
++#include <stdint.h>
+ #include <string.h>
+ #include <fcntl.h>
+ #include <errno.h>
+@@ -1198,6 +1199,34 @@ mechanism_client_initiate (GDBusAuthMechanism   *mechanism,
+   return initial_response;
+ }
+ 
++/* Context names must be valid ASCII, nonzero length, and may not contain the
++ * characters slash ("/"), backslash ("\"), space (" "), newline ("\n"),
++ * carriage return ("\r"), tab ("\t"), or period (".").
++ *
++ * See https://dbus.freedesktop.org/doc/dbus-specification.html#auth-mechanisms-sha */
++static gboolean
++validate_cookie_context (const char *cookie_context)
++{
++  size_t i = 0;
++
++  g_return_val_if_fail (cookie_context != NULL, FALSE);
++
++  for (i = 0; cookie_context[i] != '\0'; i++)
++    {
++      if ((uint8_t) cookie_context[i] >= 128 ||
++          cookie_context[i] == '/' ||
++          cookie_context[i] == '\\' ||
++          cookie_context[i] == ' ' ||
++          cookie_context[i] == '\n' ||
++          cookie_context[i] == '\r' ||
++          cookie_context[i] == '\t' ||
++          cookie_context[i] == '.')
++        return FALSE;
++    }
++
++  return (i > 0);
++}
++
+ static void
+ mechanism_client_data_receive (GDBusAuthMechanism   *mechanism,
+                                const gchar          *data,
+@@ -1232,6 +1261,14 @@ mechanism_client_data_receive (GDBusAuthMechanism   *mechanism,
+     }
+ 
+   cookie_context = tokens[0];
++  if (!validate_cookie_context (tokens[0]))
++    {
++      g_free (m->priv->reject_reason);
++      m->priv->reject_reason = g_strdup_printf ("Malformed cookie_context '%s'", tokens[0]);
++      m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED;
++      goto out;
++    }
++
+   cookie_id = g_ascii_strtoll (tokens[1], &endp, 10);
+   if (*endp != '\0')
+     {
+-- 
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
new file mode 100644
index 00000000000..28f496734a5
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
@@ -0,0 +1,55 @@
+From a94b2df7e2bc5f49661e53c2781ce99ae48d18aa Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:49:54 +0100
+Subject: [PATCH 2/4] gdbusauthmechanismsha1: Improve validation of cookie ID
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+The D-Bus specification says the cookie ID has to be non-negative, but
+we weren’t checking that (or checking that it was non-empty).
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit c0531125344bb25fd66ffb7435ed6c285de09aeb)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/gdbusauthmechanismsha1.c | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
+index 7d8fc1922..e753d139d 100644
+--- a/gio/gdbusauthmechanismsha1.c
++++ b/gio/gdbusauthmechanismsha1.c
+@@ -1235,7 +1235,7 @@ mechanism_client_data_receive (GDBusAuthMechanism   *mechanism,
+   GDBusAuthMechanismSha1 *m = G_DBUS_AUTH_MECHANISM_SHA1 (mechanism);
+   gchar **tokens;
+   const gchar *cookie_context;
+-  guint cookie_id;
++  int64_t cookie_id;
+   const gchar *server_challenge;
+   gchar *client_challenge;
+   gchar *endp;
+@@ -1270,7 +1270,7 @@ mechanism_client_data_receive (GDBusAuthMechanism   *mechanism,
+     }
+ 
+   cookie_id = g_ascii_strtoll (tokens[1], &endp, 10);
+-  if (*endp != '\0')
++  if (*endp != '\0' || endp == tokens[1] || cookie_id < 0 || cookie_id > UINT32_MAX)
+     {
+       g_free (m->priv->reject_reason);
+       m->priv->reject_reason = g_strdup_printf ("Malformed cookie_id '%s'", tokens[1]);
+@@ -1280,7 +1280,7 @@ mechanism_client_data_receive (GDBusAuthMechanism   *mechanism,
+   server_challenge = tokens[2];
+ 
+   error = NULL;
+-  cookie = keyring_lookup_entry (cookie_context, cookie_id, &error);
++  cookie = keyring_lookup_entry (cookie_context, (unsigned int) cookie_id, &error);
+   if (cookie == NULL)
+     {
+       g_free (m->priv->reject_reason);
+-- 
+2.35.6
+
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
new file mode 100644
index 00000000000..b6bd2baeb3f
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
@@ -0,0 +1,198 @@
+From 99c7abffbd1d549f6c625de6f2028efcdeea5c49 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:51:00 +0100
+Subject: [PATCH 3/4] gdbusauthmechanism: Expose client reject reason as a new
+ vfunc
+
+We can do this because `gdbusauthmechanism.h` is a private header.
+
+Hook it up to the existing `reject_reason` code in each
+`GDBusAuthMechanism` implementation, as all three implementations
+currently intermingle reject reasons from the server and client code, so
+there would currently be no benefit to having a separate server and
+client implementation of `*_get_reject_reason()`.
+
+This new private API will be used in a new unit test in the following
+commit.
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit 060aea67de7517d531b8fe2cdc07aa1a00ddeb22)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/gdbusauthmechanism.c         | 7 +++++++
+ gio/gdbusauthmechanism.h         | 2 ++
+ gio/gdbusauthmechanismanon.c     | 8 ++++----
+ gio/gdbusauthmechanismexternal.c | 8 ++++----
+ gio/gdbusauthmechanismsha1.c     | 8 ++++----
+ 5 files changed, 21 insertions(+), 12 deletions(-)
+
+diff --git a/gio/gdbusauthmechanism.c b/gio/gdbusauthmechanism.c
+index 6e494dbd9..0d4ef4389 100644
+--- a/gio/gdbusauthmechanism.c
++++ b/gio/gdbusauthmechanism.c
+@@ -328,6 +328,13 @@ _g_dbus_auth_mechanism_client_data_send (GDBusAuthMechanism *mechanism,
+   return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_data_send (mechanism, out_data_len);
+ }
+ 
++gchar *
++_g_dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism)
++{
++  g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM (mechanism), NULL);
++  return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_reject_reason (mechanism);
++}
++
+ void
+ _g_dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism)
+ {
+diff --git a/gio/gdbusauthmechanism.h b/gio/gdbusauthmechanism.h
+index f0edd19a3..e906a47ac 100644
+--- a/gio/gdbusauthmechanism.h
++++ b/gio/gdbusauthmechanism.h
+@@ -100,6 +100,7 @@ struct _GDBusAuthMechanismClass
+                                                          gsize                 data_len);
+   gchar                    *(*client_data_send)         (GDBusAuthMechanism   *mechanism,
+                                                          gsize                *out_data_len);
++  gchar                    *(*client_get_reject_reason) (GDBusAuthMechanism   *mechanism);
+   void                      (*client_shutdown)          (GDBusAuthMechanism   *mechanism);
+ };
+ 
+@@ -148,6 +149,7 @@ void                      _g_dbus_auth_mechanism_client_data_receive      (GDBus
+                                                                            gsize                 data_len);
+ gchar                    *_g_dbus_auth_mechanism_client_data_send         (GDBusAuthMechanism   *mechanism,
+                                                                           gsize                *out_data_len);
++gchar                    *_g_dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism   *mechanism);
+ void                      _g_dbus_auth_mechanism_client_shutdown          (GDBusAuthMechanism   *mechanism);
+ 
+ 
+diff --git a/gio/gdbusauthmechanismanon.c b/gio/gdbusauthmechanismanon.c
+index 5f59d4a61..3d80ec15f 100644
+--- a/gio/gdbusauthmechanismanon.c
++++ b/gio/gdbusauthmechanismanon.c
+@@ -56,7 +56,7 @@ static void                     mechanism_server_data_receive       (GDBusAuthMe
+                                                                      gsize                 data_len);
+ static gchar                   *mechanism_server_data_send          (GDBusAuthMechanism   *mechanism,
+                                                                      gsize                *out_data_len);
+-static gchar                   *mechanism_server_get_reject_reason  (GDBusAuthMechanism   *mechanism);
++static gchar                   *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism   *mechanism);
+ static void                     mechanism_server_shutdown           (GDBusAuthMechanism   *mechanism);
+ static GDBusAuthMechanismState  mechanism_client_get_state          (GDBusAuthMechanism   *mechanism);
+ static gchar                   *mechanism_client_initiate           (GDBusAuthMechanism   *mechanism,
+@@ -103,12 +103,13 @@ _g_dbus_auth_mechanism_anon_class_init (GDBusAuthMechanismAnonClass *klass)
+   mechanism_class->server_initiate           = mechanism_server_initiate;
+   mechanism_class->server_data_receive       = mechanism_server_data_receive;
+   mechanism_class->server_data_send          = mechanism_server_data_send;
+-  mechanism_class->server_get_reject_reason  = mechanism_server_get_reject_reason;
++  mechanism_class->server_get_reject_reason  = mechanism_server_or_client_get_reject_reason;
+   mechanism_class->server_shutdown           = mechanism_server_shutdown;
+   mechanism_class->client_get_state          = mechanism_client_get_state;
+   mechanism_class->client_initiate           = mechanism_client_initiate;
+   mechanism_class->client_data_receive       = mechanism_client_data_receive;
+   mechanism_class->client_data_send          = mechanism_client_data_send;
++  mechanism_class->client_get_reject_reason  = mechanism_server_or_client_get_reject_reason;
+   mechanism_class->client_shutdown           = mechanism_client_shutdown;
+ }
+ 
+@@ -222,12 +223,11 @@ mechanism_server_data_send (GDBusAuthMechanism   *mechanism,
+ }
+ 
+ static gchar *
+-mechanism_server_get_reject_reason (GDBusAuthMechanism   *mechanism)
++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism   *mechanism)
+ {
+   GDBusAuthMechanismAnon *m = G_DBUS_AUTH_MECHANISM_ANON (mechanism);
+ 
+   g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_ANON (mechanism), NULL);
+-  g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
+   g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL);
+ 
+   /* can never end up here because we are never in the REJECTED state */
+diff --git a/gio/gdbusauthmechanismexternal.c b/gio/gdbusauthmechanismexternal.c
+index 6fe8b1bed..b223ead04 100644
+--- a/gio/gdbusauthmechanismexternal.c
++++ b/gio/gdbusauthmechanismexternal.c
+@@ -64,7 +64,7 @@ static void                     mechanism_server_data_receive       (GDBusAuthMe
+                                                                      gsize                 data_len);
+ static gchar                   *mechanism_server_data_send          (GDBusAuthMechanism   *mechanism,
+                                                                      gsize                *out_data_len);
+-static gchar                   *mechanism_server_get_reject_reason  (GDBusAuthMechanism   *mechanism);
++static gchar                   *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism   *mechanism);
+ static void                     mechanism_server_shutdown           (GDBusAuthMechanism   *mechanism);
+ static GDBusAuthMechanismState  mechanism_client_get_state          (GDBusAuthMechanism   *mechanism);
+ static gchar                   *mechanism_client_initiate           (GDBusAuthMechanism   *mechanism,
+@@ -111,12 +111,13 @@ _g_dbus_auth_mechanism_external_class_init (GDBusAuthMechanismExternalClass *kla
+   mechanism_class->server_initiate           = mechanism_server_initiate;
+   mechanism_class->server_data_receive       = mechanism_server_data_receive;
+   mechanism_class->server_data_send          = mechanism_server_data_send;
+-  mechanism_class->server_get_reject_reason  = mechanism_server_get_reject_reason;
++  mechanism_class->server_get_reject_reason  = mechanism_server_or_client_get_reject_reason;
+   mechanism_class->server_shutdown           = mechanism_server_shutdown;
+   mechanism_class->client_get_state          = mechanism_client_get_state;
+   mechanism_class->client_initiate           = mechanism_client_initiate;
+   mechanism_class->client_data_receive       = mechanism_client_data_receive;
+   mechanism_class->client_data_send          = mechanism_client_data_send;
++  mechanism_class->client_get_reject_reason  = mechanism_server_or_client_get_reject_reason;
+   mechanism_class->client_shutdown           = mechanism_client_shutdown;
+ }
+ 
+@@ -321,12 +322,11 @@ mechanism_server_data_send (GDBusAuthMechanism   *mechanism,
+ }
+ 
+ static gchar *
+-mechanism_server_get_reject_reason (GDBusAuthMechanism   *mechanism)
++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism   *mechanism)
+ {
+   GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
+ 
+   g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), NULL);
+-  g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
+   g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL);
+ 
+   /* can never end up here because we are never in the REJECTED state */
+diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
+index e753d139d..6c1682d3a 100644
+--- a/gio/gdbusauthmechanismsha1.c
++++ b/gio/gdbusauthmechanismsha1.c
+@@ -120,7 +120,7 @@ static void                     mechanism_server_data_receive       (GDBusAuthMe
+                                                                      gsize                 data_len);
+ static gchar                   *mechanism_server_data_send          (GDBusAuthMechanism   *mechanism,
+                                                                      gsize                *out_data_len);
+-static gchar                   *mechanism_server_get_reject_reason  (GDBusAuthMechanism   *mechanism);
++static gchar                   *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism   *mechanism);
+ static void                     mechanism_server_shutdown           (GDBusAuthMechanism   *mechanism);
+ static GDBusAuthMechanismState  mechanism_client_get_state          (GDBusAuthMechanism   *mechanism);
+ static gchar                   *mechanism_client_initiate           (GDBusAuthMechanism   *mechanism,
+@@ -173,12 +173,13 @@ _g_dbus_auth_mechanism_sha1_class_init (GDBusAuthMechanismSha1Class *klass)
+   mechanism_class->server_initiate           = mechanism_server_initiate;
+   mechanism_class->server_data_receive       = mechanism_server_data_receive;
+   mechanism_class->server_data_send          = mechanism_server_data_send;
+-  mechanism_class->server_get_reject_reason  = mechanism_server_get_reject_reason;
++  mechanism_class->server_get_reject_reason  = mechanism_server_or_client_get_reject_reason;
+   mechanism_class->server_shutdown           = mechanism_server_shutdown;
+   mechanism_class->client_get_state          = mechanism_client_get_state;
+   mechanism_class->client_initiate           = mechanism_client_initiate;
+   mechanism_class->client_data_receive       = mechanism_client_data_receive;
+   mechanism_class->client_data_send          = mechanism_client_data_send;
++  mechanism_class->client_get_reject_reason  = mechanism_server_or_client_get_reject_reason;
+   mechanism_class->client_shutdown           = mechanism_client_shutdown;
+ }
+ 
+@@ -1129,12 +1130,11 @@ mechanism_server_data_send (GDBusAuthMechanism   *mechanism,
+ }
+ 
+ static gchar *
+-mechanism_server_get_reject_reason (GDBusAuthMechanism   *mechanism)
++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism)
+ {
+   GDBusAuthMechanismSha1 *m = G_DBUS_AUTH_MECHANISM_SHA1 (mechanism);
+ 
+   g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_SHA1 (mechanism), NULL);
+-  g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
+   g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL);
+ 
+   return g_strdup (m->priv->reject_reason);
+-- 
+2.35.6
+
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch
new file mode 100644
index 00000000000..0785ad3c3a6
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch
@@ -0,0 +1,222 @@
+From 80d2edcc14f476d0ec82dc0733964afa6e9ca74d Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:52:53 +0100
+Subject: [PATCH 4/4] tests: Add a unit test for GDBusAuthMechanismSha1 cookie
+ context parsing
+
+This checks for regressions in the fixes from the previous few commits.
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277]
+
+Backport Changes:
+- Replaced the literal U+1F600 test string with its UTF-8 byte escapes to
+  avoid the observed Patchwork mbox truncation. The test input is unchanged.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+Helps: #3931
+(cherry picked from commit 0919301962291a712067ee0c5d273cc392f33277)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/tests/gdbus-auth-mechanism-sha1.c | 177 ++++++++++++++++++++++++++
+ gio/tests/meson.build                 |   1 +
+ 2 files changed, 178 insertions(+)
+ create mode 100644 gio/tests/gdbus-auth-mechanism-sha1.c
+
+diff --git a/gio/tests/gdbus-auth-mechanism-sha1.c b/gio/tests/gdbus-auth-mechanism-sha1.c
+new file mode 100644
+index 000000000..abcdb4e3e
+--- /dev/null
++++ b/gio/tests/gdbus-auth-mechanism-sha1.c
+@@ -0,0 +1,177 @@
++/* GLib testing framework examples and tests
++ *
++ * Copyright (C) 2026 Philip Withnall
++ *
++ * SPDX-License-Identifier: LGPL-2.1-or-later
++ *
++ * This library is free software; you can redistribute it and/or
++ * modify it under the terms of the GNU Lesser General Public
++ * License as published by the Free Software Foundation; either
++ * version 2.1 of the License, or (at your option) any later version.
++ *
++ * This library is distributed in the hope that it will be useful,
++ * but WITHOUT ANY WARRANTY; without even the implied warranty of
++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
++ * Lesser General Public License for more details.
++ *
++ * You should have received a copy of the GNU Lesser General
++ * Public License along with this library; if not, see <http://www.gnu.org/licenses/>.
++ *
++ * Author: Philip Withnall <pwithnall@gnome.org>
++ */
++
++#include <locale.h>
++#include <gio/gio.h>
++
++#include <string.h>
++#include <unistd.h>
++
++#include "gdbus-tests.h"
++
++#ifdef G_OS_UNIX
++#include <gio/gunixconnection.h>
++#include <gio/gnetworkingprivate.h>
++#include <gio/gunixsocketaddress.h>
++#include <gio/gunixfdlist.h>
++#endif
++
++#define GIO_COMPILATION 1
++#include "gdbusauthmechanism.h"
++#include "gdbusauthmechanismsha1.h"
++
++/* Vfunc wrappers copied from gdbusauthmechanism.c as they are not public. */
++static gboolean
++dbus_auth_mechanism_is_supported (GDBusAuthMechanism *mechanism)
++{
++  return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->is_supported (mechanism);
++}
++
++static GDBusAuthMechanismState
++dbus_auth_mechanism_client_get_state (GDBusAuthMechanism *mechanism)
++{
++  return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_state (mechanism);
++}
++
++static gchar *
++dbus_auth_mechanism_client_initiate (GDBusAuthMechanism   *mechanism,
++                                     GDBusConnectionFlags  conn_flags,
++                                     size_t               *out_initial_response_len)
++{
++  return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_initiate (mechanism,
++                                                                       conn_flags,
++                                                                       out_initial_response_len);
++}
++
++static void
++dbus_auth_mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
++                                         const char         *data,
++                                         size_t              data_len)
++{
++  G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_data_receive (mechanism, data, data_len);
++}
++
++static char *
++dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism)
++{
++  return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_reject_reason (mechanism);
++}
++
++static void
++dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism)
++{
++  G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_shutdown (mechanism);
++}
++
++static void
++test_server_challenge_validation (void)
++{
++  const struct
++    {
++      const char *server_challenge;
++      const char *expected_reject_reason_prefix;
++    }
++  vectors[] = {
++    { "valid_context 123 456", "Problems looking up entry in keyring" },
++    { "invalid/context 123 456", "Malformed cookie_context" },
++    { "invalid.context 123 456", "Malformed cookie_context" },
++    { " 123 456", "Malformed cookie_context" },
++    { "\xF0\x9F\x98\x80" " 123 456", "Malformed cookie_context" },
++    { "invalid\ncontext 123 456", "Malformed cookie_context" },
++    { "invalid\rcontext 123 456", "Malformed cookie_context" },
++    { "invalid\tcontext 123 456", "Malformed cookie_context" },
++    { "invalid\\context 123 456", "Malformed cookie_context" },
++    { "valid_context  456", "Malformed cookie_id" },
++    { "valid_context 123notanumber 456", "Malformed cookie_id" },
++    { "valid_context -1 456", "Malformed cookie_id" },
++    { "valid_context 4294967296 456", "Malformed cookie_id" },
++    { "valid_context 123  ", "Malformed data" },
++    { "valid_context ", "Malformed data" },
++  };
++  GType mechanism_type;
++  GDBusConnection *connection = NULL;
++
++  g_test_summary ("Test that GDBusAuthMechanismSha1 rejects various malformed server data lines");
++
++  /* Briefly connect to the actual bus to ensure the GDBusAuth mechanisms are
++   * all registered. */
++  session_bus_up ();
++
++  connection = g_bus_get_sync (G_BUS_TYPE_SESSION, NULL, NULL);
++  g_assert_nonnull (connection);
++  g_clear_object (&connection);
++
++  session_bus_down ();
++
++  /* Check that we now have the type ID for GDBusAuthMechanismSha1 */
++  mechanism_type = g_type_from_name ("GDBusAuthMechanismSha1");
++  g_assert_cmpint (mechanism_type,  !=, 0);
++
++  for (size_t i = 0; i < G_N_ELEMENTS (vectors); i++)
++    {
++      GDBusAuthMechanism *mechanism = NULL;
++      char *data = NULL;
++      size_t data_len = 0;
++      char *reject_reason = NULL;
++
++      mechanism = g_object_new (mechanism_type, NULL);
++
++      if (!dbus_auth_mechanism_is_supported (mechanism))
++        {
++          g_test_skip ("Mechanism not supported");
++          g_clear_object (&mechanism);
++          return;
++        }
++
++      data = dbus_auth_mechanism_client_initiate (mechanism,
++                                                  G_DBUS_CONNECTION_FLAGS_AUTHENTICATION_CLIENT,
++                                                  &data_len);
++      g_free (data);
++
++      dbus_auth_mechanism_client_data_receive (mechanism, vectors[i].server_challenge, strlen (vectors[i].server_challenge));
++
++      g_assert_cmpint (dbus_auth_mechanism_client_get_state (mechanism), ==, G_DBUS_AUTH_MECHANISM_STATE_REJECTED);
++
++      reject_reason = dbus_auth_mechanism_client_get_reject_reason (mechanism);
++      g_assert_true (g_str_has_prefix (reject_reason, vectors[i].expected_reject_reason_prefix));
++      g_free (reject_reason);
++
++      dbus_auth_mechanism_client_shutdown (mechanism);
++
++      g_clear_object (&mechanism);
++    }
++}
++
++int
++main (int   argc,
++      char *argv[])
++{
++  setlocale (LC_ALL, "C");
++
++  g_test_init (&argc, &argv, G_TEST_OPTION_ISOLATE_DIRS, NULL);
++
++  g_test_dbus_unset ();
++
++  g_test_add_func ("/gdbus/auth-mechanism-sha1/server-challenge-validation", test_server_challenge_validation);
++
++  return g_test_run ();
++}
+diff --git a/gio/tests/meson.build b/gio/tests/meson.build
+index e7699c336..74ea481ff 100644
+--- a/gio/tests/meson.build
++++ b/gio/tests/meson.build
+@@ -418,6 +418,7 @@ if host_system != 'windows'
+       },
+       'fdo-notification-backend': {},
+       'gdbus-auth' : {'extra_sources' : extra_sources},
++      'gdbus-auth-mechanism-sha1': {'extra_sources' : extra_sources},
+       'gdbus-bz627724' : {'extra_sources' : extra_sources},
+       'gdbus-close-pending' : {'extra_sources' : extra_sources},
+       'gdbus-connection' : {
+-- 
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index e15aa1fe206..70b0b74e881 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -54,6 +54,10 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
            file://CVE-2026-58012.patch \
            file://CVE-2026-58013.patch \
            file://CVE-2026-58014.patch \
+           file://CVE-2026-58015_p1.patch \
+           file://CVE-2026-58015_p2.patch \
+           file://CVE-2026-58015_p3.patch \
+           file://CVE-2026-58015_p4.patch \
            "
 SRC_URI:append:class-native = " file://relocate-modules.patch \
                                 file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
diff --git a/meta/recipes-core/glib-2.0/glib.inc b/meta/recipes-core/glib-2.0/glib.inc
index fac8875d844..5b69c9d7d3e 100644
--- a/meta/recipes-core/glib-2.0/glib.inc
+++ b/meta/recipes-core/glib-2.0/glib.inc
@@ -39,7 +39,7 @@ PACKAGECONFIG ??= "libmount \
 PACKAGECONFIG[libmount] = "-Dlibmount=enabled,-Dlibmount=disabled,util-linux"
 PACKAGECONFIG[manpages] = "-Dman=true, -Dman=false, libxslt-native xmlto-native"
 PACKAGECONFIG[libelf] = "-Dlibelf=enabled,-Dlibelf=disabled,elfutils"
-PACKAGECONFIG[tests] = "-Dinstalled_tests=true,-Dinstalled_tests=false,"
+PACKAGECONFIG[tests] = "-Dinstalled_tests=true,-Dinstalled_tests=false,dbus-native"
 PACKAGECONFIG[selinux] = "-Dselinux=enabled,-Dselinux=disabled,libselinux"
 
 EXTRA_OEMESON = "-Ddtrace=false -Dsystemtap=false"


^ permalink raw reply related	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 08/11] curl: fix CVE-2025-10148 backport for websockets on 8.7.1
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
                   ` (6 preceding siblings ...)
  2026-08-25 10:06 ` [OE-core][scarthgap 07/11] glib-2.0: fix CVE-2026-58015 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 09/11] bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES Yoann Congal
                   ` (2 subsequent siblings)
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Etienne Cordonnier <ecordonnier@snap.com>

The original backport applied upstream's CURLcode return path into
ssize_t ws_enc_write_head(), which uses an undeclared result and is
invalid for curl 8.7.1's API. Builds with --enable-websockets fail.

Adapt Curl_rand() error handling to set *err and return -1.

AI-Generated: Claude Sonnet 4.6
Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 .../curl/curl/CVE-2025-10148.patch            | 24 +++++++++++--------
 1 file changed, 14 insertions(+), 10 deletions(-)

diff --git a/meta/recipes-support/curl/curl/CVE-2025-10148.patch b/meta/recipes-support/curl/curl/CVE-2025-10148.patch
index d37497febe9..654f4151e99 100644
--- a/meta/recipes-support/curl/curl/CVE-2025-10148.patch
+++ b/meta/recipes-support/curl/curl/CVE-2025-10148.patch
@@ -9,23 +9,28 @@ Closes #18496
 CVE: CVE-2025-10148
 Upstream-Status: Backport [https://github.com/curl/curl/commit/84db7a9eae8468c0445b15aa806fa]
 Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
 ---
- lib/ws.c | 21 +++++++++++++--------
- 1 file changed, 13 insertions(+), 8 deletions(-)
+ lib/ws.c | 25 +++++++++++++++++--------
+ 1 file changed, 17 insertions(+), 8 deletions(-)
 
 diff --git a/lib/ws.c b/lib/ws.c
 index 5bc5ecc..02e0ef0 100644
 --- a/lib/ws.c
 +++ b/lib/ws.c
-@@ -614,6 +614,18 @@ static ssize_t ws_enc_write_head(struct Curl_easy *data,
+@@ -614,6 +614,22 @@ static ssize_t ws_enc_write_head(struct Curl_easy *data,
    enc->payload_remain = enc->payload_len = payload_len;
    ws_enc_info(enc, data, "sending");
  
-+    /* 4 bytes random */
-+
-+  result = Curl_rand(data, (unsigned char *)&enc->mask, sizeof(enc->mask));
-+  if(result)
-+    return result;
++  /* 4 bytes random */
++  {
++    CURLcode result = Curl_rand(data, (unsigned char *)&enc->mask,
++                                sizeof(enc->mask));
++    if(result) {
++      *err = result;
++      return -1;
++    }
++  }
 +
 +#ifdef DEBUGBUILD
 +  if(getenv("CURL_WS_FORCE_ZERO_MASK"))
@@ -36,7 +41,7 @@ index 5bc5ecc..02e0ef0 100644
    /* add 4 bytes mask */
    memcpy(&head[hlen], &enc->mask, 4);
    hlen += 4;
-@@ -802,14 +814,7 @@ CURLcode Curl_ws_accept(struct Curl_easy *data,
+@@ -802,14 +818,7 @@ CURLcode Curl_ws_accept(struct Curl_easy *data,
       subprotocol not requested by the client), the client MUST Fail
       the WebSocket Connection. */
  
@@ -54,4 +59,3 @@ index 5bc5ecc..02e0ef0 100644
    result = Curl_cwriter_create(&ws_dec_writer, data, &ws_cw_decode,
 -- 
 2.50.1
-


^ permalink raw reply related	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 09/11] bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
                   ` (7 preceding siblings ...)
  2026-08-25 10:06 ` [OE-core][scarthgap 08/11] curl: fix CVE-2025-10148 backport for websockets on 8.7.1 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 10/11] bison: patch CVE-2026-56389 Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 11/11] rpcbind: Fix CVE-2026-16277 Yoann Congal
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Ross Burton <ross.burton@arm.com>

We export GIT_CEILING_DIRECTORIES=WORKDIR to ensure that git calls
inside the builds don't find oe-core when they're meant to be looking
for the git repository of the source code.

However, this breaks for recipes that use work-shared (such as llvm), as
their working directory is outside of WORKDIR.

Solve this by adding TMPDIR to the list as a final catch, but keeping
WORKDIR first so that git will stop sooner in the general case.

This solves reproduciblity problems in LLVM, where for example lld's
version string would contain the URL and commit hash of the poky repo
being built.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit f42f0185bd00e68ecc86a930487f21fc86214cfa)
Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
[fatho: edit commit message by adding "cherry picked from"]
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 meta/conf/bitbake.conf | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/meta/conf/bitbake.conf b/meta/conf/bitbake.conf
index e20b17fad6f..3fd442edbdd 100644
--- a/meta/conf/bitbake.conf
+++ b/meta/conf/bitbake.conf
@@ -786,9 +786,9 @@ export PKG_CONFIG_DISABLE_UNINSTALLED = "yes"
 export PKG_CONFIG_SYSTEM_LIBRARY_PATH = "${base_libdir}:${libdir}"
 export PKG_CONFIG_SYSTEM_INCLUDE_PATH = "${includedir}"
 
-# Don't allow git to chdir up past WORKDIR so that it doesn't detect the OE
-# repository when building a recipe
-export GIT_CEILING_DIRECTORIES = "${WORKDIR}"
+# Don't allow git to chdir up past WORKDIR or TMPDIR so that it doesn't detect the OE
+# repository when building a recipe.
+export GIT_CEILING_DIRECTORIES = "${WORKDIR}:${TMPDIR}"
 
 ###
 ### Config file processing


^ permalink raw reply related	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 10/11] bison: patch CVE-2026-56389
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
                   ` (8 preceding siblings ...)
  2026-08-25 10:06 ` [OE-core][scarthgap 09/11] bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  2026-08-25 10:06 ` [OE-core][scarthgap 11/11] rpcbind: Fix CVE-2026-16277 Yoann Congal
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Peter Marko <peter.marko@siemens.com>

Pick patch mentioned in NVD CVE report.

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 6c99410bd7f0bc4e2ed41ef5afe7d6b5fcb99837)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 .../bison/bison/CVE-2026-56389.patch          | 56 +++++++++++++++++++
 meta/recipes-devtools/bison/bison_3.8.2.bb    |  1 +
 2 files changed, 57 insertions(+)
 create mode 100644 meta/recipes-devtools/bison/bison/CVE-2026-56389.patch

diff --git a/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch b/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch
new file mode 100644
index 00000000000..ac827f6314a
--- /dev/null
+++ b/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch
@@ -0,0 +1,56 @@
+From 3169c1e7a2c6acc4c59dfcf8b089896d6881925b Mon Sep 17 00:00:00 2001
+From: Paul Eggert <eggert@cs.ucla.edu>
+Date: Thu, 23 Apr 2026 09:20:43 -0700
+Subject: [PATCH] html: use xsltproc from PATH
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+* src/print-xml.c (print_html):
+* src/reader.c (prepare_percent_define_front_end_variables):
+Drop undocumented support for lines like ‘%define tool.xsltproc
+"whatever"’, as this can cause more trouble than it cures.
+
+CVE: CVE-2026-56389
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=3169c1e7a2c6acc4c59dfcf8b089896d6881925b]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/print-xml.c | 4 +---
+ src/reader.c    | 1 -
+ 2 files changed, 1 insertion(+), 4 deletions(-)
+
+diff --git a/src/print-xml.c b/src/print-xml.c
+index 8da6da0d..79bfa88d 100644
+--- a/src/print-xml.c
++++ b/src/print-xml.c
+@@ -543,10 +543,9 @@ print_html (void)
+   assert (xml_flag);
+ 
+   char *xml2html = xpath_join (pkgdatadir (), "xslt/xml2xhtml.xsl");
+-  char *xsltproc = muscle_percent_define_get ("tool.xsltproc");
+   char const *argv[11];
+   int i = 0;
+-  argv[i++] = xsltproc;
++  argv[i++] = "xsltproc";
+   argv[i++] = "-o";
+   argv[i++] = spec_html_file;
+   argv[i++] = xml2html;
+@@ -572,6 +571,5 @@ print_html (void)
+                /* termsigp */ NULL);
+   if (status)
+     complain (NULL, complaint, _("%s failed with status %d"), argv[0], status);
+-  free (xsltproc);
+   free (xml2html);
+ }
+diff --git a/src/reader.c b/src/reader.c
+index 862d7293..cb2a7f69 100644
+--- a/src/reader.c
++++ b/src/reader.c
+@@ -788,7 +788,6 @@ prepare_percent_define_front_end_variables (void)
+       muscle_percent_define_default ("lr.default-reduction", "accepting");
+     free (lr_type);
+   }
+-  muscle_percent_define_default ("tool.xsltproc", "xsltproc");
+ 
+   /* Check %define front-end variables.  */
+   {
diff --git a/meta/recipes-devtools/bison/bison_3.8.2.bb b/meta/recipes-devtools/bison/bison_3.8.2.bb
index da138e35874..9808a96e993 100644
--- a/meta/recipes-devtools/bison/bison_3.8.2.bb
+++ b/meta/recipes-devtools/bison/bison_3.8.2.bb
@@ -12,6 +12,7 @@ DEPENDS = "bison-native flex-native"
 SRC_URI = "${GNU_MIRROR}/bison/bison-${PV}.tar.xz \
            file://autoconf-2.73.patch \
            file://add-with-bisonlocaledir.patch \
+           file://CVE-2026-56389.patch \
            "
 SRC_URI[sha256sum] = "9bba0214ccf7f1079c5d59210045227bcf619519840ebfa80cd3849cff5a5bf2"
 


^ permalink raw reply related	[flat|nested] 25+ messages in thread

* [OE-core][scarthgap 11/11] rpcbind: Fix CVE-2026-16277
  2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
                   ` (9 preceding siblings ...)
  2026-08-25 10:06 ` [OE-core][scarthgap 10/11] bison: patch CVE-2026-56389 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
  10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
  To: openembedded-core

From: Vijay Anusuri <vanusuri@mvista.com>

Pick patch according to [2]

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-16277
[2] https://security-tracker.debian.org/tracker/CVE-2026-16277

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
 .../rpcbind/rpcbind/CVE-2026-16277.patch      | 34 +++++++++++++++++++
 .../recipes-extended/rpcbind/rpcbind_1.2.6.bb |  1 +
 2 files changed, 35 insertions(+)
 create mode 100644 meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch

diff --git a/meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch b/meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch
new file mode 100644
index 00000000000..868e5c3f01c
--- /dev/null
+++ b/meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch
@@ -0,0 +1,34 @@
+From bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d Mon Sep 17 00:00:00 2001
+From: Steve Dickson <steved@redhat.com>
+Date: Wed, 27 May 2026 11:42:11 -0400
+Subject: [PATCH] rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist()
+
+rpcinfo's rpcbaddrlist() formats two server-controlled, unbounded XDR strings into a fixed 128-byte stack buffer with sprintf(). A malicious or on-path rpcbind server overflows it when a user runs:
+rpcinfo -l <host> <prognum> <versnum>
+
+Reported-by: Michalis Vasileiadis <vmihalis.tmd@gmail.com>
+Signed-off-by: Steve Dickson <steved@redhat.com>
+
+Upstream-Status: Backport [https://git.linux-nfs.org/?p=steved/rpcbind.git;a=commitdiff;h=bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d]
+CVE: CVE-2026-16277
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/rpcinfo.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/rpcinfo.c b/src/rpcinfo.c
+index 0e14f78..43e8115 100644
+--- a/src/rpcinfo.c
++++ b/src/rpcinfo.c
+@@ -1120,7 +1120,7 @@ rpcbaddrlist (netid, argc, argv)
+ 
+ 	  re = &head->rpcb_entry_map;
+ 	  printf ("%10u%3u    ", parms.r_prog, parms.r_vers);
+-	  sprintf (buf, "%s/%s/%s ",
++	  snprintf (buf, sizeof(buf), "%s/%s/%s ",
+ 		   re->r_nc_protofmly, re->r_nc_proto,
+ 		   re->r_nc_semantics == NC_TPI_CLTS ? "clts" :
+ 		   re->r_nc_semantics == NC_TPI_COTS ? "cots" : "cots_ord");
+-- 
+2.43.0
+
diff --git a/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb b/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb
index dbd4d32e0a0..07e2f10c98a 100644
--- a/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb
+++ b/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb
@@ -15,6 +15,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/rpcbind/rpcbind-${PV}.tar.bz2 \
            file://rpcbind.conf \
            file://rpcbind_add_option_to_fix_port_number.patch \
            file://0001-systemd-use-EnvironmentFile.patch \
+           file://CVE-2026-16277.patch \
           "
 SRC_URI[sha256sum] = "5613746489cae5ae23a443bb85c05a11741a5f12c8f55d2bb5e83b9defeee8de"
 


^ permalink raw reply related	[flat|nested] 25+ messages in thread

end of thread, other threads:[~2026-08-25 10:07 UTC | newest]

Thread overview: 25+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 01/11] nghttp2: set status for CVE-2026-58055 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 02/11] binutils: fix CVE-2025-1147 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 03/11] binutils: fix CVE-2025-8224 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 04/11] binutils: fix CVE-2026-15003 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 05/11] binutils: fix CVE-2026-18220 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 06/11] libssh2: fix CVE-2026-58050 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 07/11] glib-2.0: fix CVE-2026-58015 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 08/11] curl: fix CVE-2025-10148 backport for websockets on 8.7.1 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 09/11] bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 10/11] bison: patch CVE-2026-56389 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 11/11] rpcbind: Fix CVE-2026-16277 Yoann Congal
  -- strict thread matches above, loose matches on Subject: below --
2026-03-29 22:46 [OE-core][scarthgap 00/11] Patch review Yoann Congal
2026-03-30  7:33 ` Yoann Congal
2026-04-20  8:44 ` Joao Marcos Costa
2026-04-20  9:21   ` Yoann Congal
2026-04-20 10:51     ` Joao Marcos Costa
2026-03-07 22:52 Yoann Congal
2026-03-09  8:18 ` Paul Barker
2025-09-25 13:40 Steve Sakoman
2025-07-30 21:28 Steve Sakoman
2025-07-04 15:10 Steve Sakoman
2025-05-28 14:43 Steve Sakoman
2024-10-25 18:29 Steve Sakoman
2024-09-16  2:19 Steve Sakoman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.