From: Yoann Congal <yoann.congal@smile.fr>
To: openembedded-core@lists.openembedded.org
Subject: [OE-core][scarthgap 00/27] Patch review
Date: Wed, 2 Sep 2026 07:25:17 +0200 [thread overview]
Message-ID: <cover.1788326578.git.yoann.congal@smile.fr> (raw)
Please review this set of changes for scarthgap and have comments back by
end of day Thursday, September 3.
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/4636
The following changes since commit 310eec2cb646d7d1a3ca99bad7e37495bb418a0d:
build-appliance-image: Update to scarthgap head revision (2026-08-28 09:52:39 +0100)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut
for you to fetch changes up to 1b1e13055b4eed838e1411d91dea46de08e1d72f:
patch: Fix CVE-2026-56288 (2026-09-01 17:07:13 +0200)
----------------------------------------------------------------
Emily Vekariya (2):
python3-pyasn1: Fix CVE-2026-59886
python3-pyasn1: Fix CVE-2026-59884
Hemanth Kumar M D (1):
glibc: fix CVE-2026-5435
Hetvi Thakar (5):
wget: Fix CVE-2026-58469
wget: Fix CVE-2026-58471
wget: Fix CVE-2026-58472
patch: Fix CVE-2026-56289
patch: Fix CVE-2026-56288
Jaipaul Cheernam (4):
systemd: Fix CVE-2026-29111
perl: fix CVE-2026-13221
perl: fix CVE-2026-57432
perl: fix CVE-2025-40909
Martin Jansa (1):
socat: fix native build on host with newer glibc
Peter Marko (5):
python3: upgrade 3.12.13 -> 3.12.14
systemd: upgrade 255.21 -> 255.22
libarchive: handle CVE-2026-5121
libarchive: patch CVE-2026-5745
gnutls: set status for CVE-2026-1584
Siddharth Doshi (9):
vim: Security Fix for CVE-2026-55693
vim: Security Fix for CVE-2026-55892
vim: Security Fix for CVE-2026-55895
vim: Security Fix for CVE-2026-57452
vim: Security Fix for CVE-2026-57455
vim: Security Fix for CVE-2026-59856
vim: Security Fix for CVE-2026-59857
vim: Security Fix for CVE-2026-59858
vim: Security Fix for CVE-2026-57456
...ixed-strchr-with-const-for-new-glibc.patch | 38 +
.../socat/socat_1.8.0.0.bb | 1 +
.../glibc/glibc/0024-CVE-2026-5435.patch | 137 ++
meta/recipes-core/glibc/glibc_2.39.bb | 1 +
...55.21.bb => systemd-boot-native_255.22.bb} | 0
...-boot_255.21.bb => systemd-boot_255.22.bb} | 0
meta/recipes-core/systemd/systemd.inc | 2 +-
.../systemd/systemd/CVE-2026-29111-01.patch | 170 +++
.../systemd/systemd/CVE-2026-29111-02.patch | 85 ++
.../systemd/systemd/CVE-2026-29111-03.patch | 106 ++
.../systemd/systemd/CVE-2026-29111-04.patch | 35 +
.../{systemd_255.21.bb => systemd_255.22.bb} | 4 +
.../patch/patch/CVE-2026-56288.patch | 75 +
.../patch/patch/CVE-2026-56289.patch | 36 +
meta/recipes-devtools/patch/patch_2.7.6.bb | 2 +
.../perl-cross/files/CVE-2025-40909-dep.patch | 25 +
.../perl-cross/perlcross_1.6.2.bb | 1 +
.../perl/files/CVE-2025-40909.patch | 412 ++++++
.../perl/files/CVE-2026-13221.patch | 75 +
.../perl/files/CVE-2026-57432-01.patch | 52 +
.../perl/files/CVE-2026-57432-02.patch | 34 +
meta/recipes-devtools/perl/perl_5.38.4.bb | 4 +
.../recipes-devtools/python/python-pyasn1.inc | 2 +
.../python3-pyasn1/CVE-2026-59884.patch | 245 ++++
.../python3-pyasn1/CVE-2026-59886.patch | 252 ++++
...shebang-overflow-on-python-config.py.patch | 2 +-
...-qemu-wrapper-when-gathering-profile.patch | 2 +-
...e-treat-overflow-in-UID-GID-as-failu.patch | 2 +-
.../python/python3/CVE-2025-13462.patch | 142 --
.../python/python3/CVE-2026-11940.patch | 66 -
.../python/python3/CVE-2026-11972.patch | 60 -
.../python/python3/CVE-2026-1502.patch | 113 --
.../python3/CVE-2026-3644_CVE-2026-0672.patch | 154 --
.../python/python3/CVE-2026-4224.patch | 121 --
.../python3/CVE-2026-4519_CVE-2026-4786.patch | 66 -
.../python/python3/CVE-2026-4519_p1.patch | 107 --
.../python/python3/CVE-2026-4519_p2.patch | 159 ---
.../python/python3/CVE-2026-6100.patch | 75 -
.../python/python3/CVE-2026-7210.patch | 148 --
.../python/python3/CVE-2026-9669.patch | 96 --
.../python/python3/makerace.patch | 2 +-
...{python3_3.12.13.bb => python3_3.12.14.bb} | 24 +-
...atch => CVE-2026-4426_CVE-2026-5121.patch} | 1 +
.../libarchive/CVE-2026-5121-02.patch | 1270 +++++++++++++++++
.../libarchive/libarchive/CVE-2026-5745.patch | 39 +
.../libarchive/libarchive_3.7.9.bb | 4 +-
.../wget/CVE-2026-58469-regression_p1.patch | 39 +
.../wget/CVE-2026-58469-regression_p2.patch | 26 +
.../wget/wget/CVE-2026-58469.patch | 53 +
.../wget/wget/CVE-2026-58471.patch | 71 +
.../wget/wget/CVE-2026-58472-regression.patch | 236 +++
.../wget/wget/CVE-2026-58472.patch | 77 +
meta/recipes-extended/wget/wget_1.21.4.bb | 6 +
meta/recipes-support/gnutls/gnutls_3.8.4.bb | 1 +
.../vim/files/CVE-2026-55693.patch | 88 ++
.../vim/files/CVE-2026-55892.patch | 81 ++
.../vim/files/CVE-2026-55895.patch | 53 +
.../vim/files/CVE-2026-57452.patch | 76 +
.../vim/files/CVE-2026-57455.patch | 72 +
.../vim/files/CVE-2026-57456.patch | 90 ++
.../vim/files/CVE-2026-59856.patch | 103 ++
.../vim/files/CVE-2026-59857.patch | 110 ++
.../vim/files/CVE-2026-59858.patch | 134 ++
meta/recipes-support/vim/vim.inc | 9 +
64 files changed, 4444 insertions(+), 1328 deletions(-)
create mode 100644 meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch
create mode 100644 meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch
rename meta/recipes-core/systemd/{systemd-boot-native_255.21.bb => systemd-boot-native_255.22.bb} (100%)
rename meta/recipes-core/systemd/{systemd-boot_255.21.bb => systemd-boot_255.22.bb} (100%)
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch
rename meta/recipes-core/systemd/{systemd_255.21.bb => systemd_255.22.bb} (99%)
create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56288.patch
create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56289.patch
create mode 100644 meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2025-40909.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch
create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2025-13462.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11940.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11972.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-1502.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4224.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-6100.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-7210.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-9669.patch
rename meta/recipes-devtools/python/{python3_3.12.13.bb => python3_3.12.14.bb} (96%)
rename meta/recipes-extended/libarchive/libarchive/{CVE-2026-4426.patch => CVE-2026-4426_CVE-2026-5121.patch} (99%)
create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch
create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58471.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55693.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55895.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57456.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59856.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59857.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
next reply other threads:[~2026-09-02 5:26 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 5:25 Yoann Congal [this message]
2026-09-02 5:25 ` [OE-core][scarthgap 01/27] socat: fix native build on host with newer glibc Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 02/27] glibc: fix CVE-2026-5435 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 03/27] systemd: Fix CVE-2026-29111 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 04/27] python3-pyasn1: Fix CVE-2026-59886 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 05/27] python3-pyasn1: Fix CVE-2026-59884 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 06/27] python3: upgrade 3.12.13 -> 3.12.14 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 07/27] systemd: upgrade 255.21 -> 255.22 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 08/27] libarchive: handle CVE-2026-5121 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 09/27] libarchive: patch CVE-2026-5745 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 10/27] gnutls: set status for CVE-2026-1584 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 11/27] perl: fix CVE-2026-13221 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 12/27] perl: fix CVE-2026-57432 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 13/27] perl: fix CVE-2025-40909 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 14/27] wget: Fix CVE-2026-58469 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 15/27] wget: Fix CVE-2026-58471 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 16/27] wget: Fix CVE-2026-58472 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 17/27] vim: Security Fix for CVE-2026-55693 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 18/27] vim: Security Fix for CVE-2026-55892 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 19/27] vim: Security Fix for CVE-2026-55895 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 20/27] vim: Security Fix for CVE-2026-57452 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 21/27] vim: Security Fix for CVE-2026-57455 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 22/27] vim: Security Fix for CVE-2026-59856 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 23/27] vim: Security Fix for CVE-2026-59857 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 24/27] vim: Security Fix for CVE-2026-59858 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 25/27] vim: Security Fix for CVE-2026-57456 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 26/27] patch: Fix CVE-2026-56289 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 27/27] patch: Fix CVE-2026-56288 Yoann Congal
-- strict thread matches above, loose matches on Subject: below --
2024-11-21 21:53 [OE-core][scarthgap 00/27] Patch review Steve Sakoman
2024-09-30 1:56 Steve Sakoman
2024-07-14 12:38 Steve Sakoman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cover.1788326578.git.yoann.congal@smile.fr \
--to=yoann.congal@smile.fr \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.