* [PATCH 00/14] Scarthgap pull request
@ 2026-09-30 14:06 Anuj Mittal
2026-10-01 2:13 ` [oe] " Khem Raj
0 siblings, 1 reply; 3+ messages in thread
From: Anuj Mittal @ 2026-09-30 14:06 UTC (permalink / raw)
To: openembedded-devel
Please review and merge these changes in scarthgap. Tested on autobuilder
and locally:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/81/builds/1836
The following changes since commit b5874ea07d69919d9b40d59f2c2f0bbd24bc3259:
libssh: Fix CVE-2026-59850 (2026-09-02 10:39:59 +0530)
are available in the Git repository at:
https://git.openembedded.org/meta-openembedded-contrib anujm/scarthgap
https://git.openembedded.org/meta-openembedded-contrib/log/?h=anujm/scarthgap
for you to fetch changes up to 0f00f8b9a21950640da8c5707343e5540133f86e:
vboxguestdrivers: fix vboxvideo build on kernels lacking drm_fb_helper_alloc_info (2026-09-29 16:10:23 +0530)
----------------------------------------------------------------
Anuj Mittal (1):
vboxguestdrivers: fix vboxvideo build on kernels lacking
drm_fb_helper_alloc_info
Benjamin Robin (Schneider Electric) (2):
libwebsockets: update to version 4.3.10
libwebsockets: fix CVE-2026-19773
Deepak Rathore (1):
rsyslog: Fix CVE-2026-19654
Himani Ramesh Barde (1):
postfix: fix build on hosts with Linux 7.x kernel
Hitendra Prajapati (1):
python3-pillow: fix CVE-2026-42311
Jason Schonberg (1):
php: upgrade 8.2.33 -> 8.2.34
Peter Marko (3):
msgpack-c: patch CVE-2026-72854
recipes: correct homepage
polkit: patch CVE-2026-4897 and CVE-2026-85498
Rohini Sangam (2):
python3-pillow: Security fix for CVE-2026-59198
python3-pillow: Security fix for CVE-2026-59204
Viswanath Kraleti (1):
libfastjson: switch git branch from master to main
Yogita Urade (1):
hdf5: Fix CVE-2026-17572
...kedefs-Account-for-linux-7.x-version.patch | 47 +++
.../recipes-daemons/postfix/postfix_3.8.19.bb | 1 +
.../libwebsockets/CVE-2025-11677.patch | 161 --------
.../libwebsockets/CVE-2025-11678.patch | 128 -------
.../libwebsockets/CVE-2026-19773.patch | 32 ++
...ckets_4.3.3.bb => libwebsockets_4.3.10.bb} | 7 +-
.../msgpack/msgpack-c/CVE-2026-72854.patch | 127 +++++++
.../msgpack/msgpack-c_6.0.0.bb | 1 +
.../php/{php_8.2.33.bb => php_8.2.34.bb} | 2 +-
.../polkit/files/CVE-2026-4897-01.patch | 64 ++++
.../polkit/files/CVE-2026-4897-02.patch | 32 ++
.../polkit/files/CVE-2026-85498.patch | 38 ++
meta-oe/recipes-extended/polkit/polkit_124.bb | 3 +
.../rsyslog/libfastjson_1.2304.0.bb | 2 +-
.../rsyslog/CVE-2026-19654-regression.patch | 56 +++
.../rsyslog/rsyslog/CVE-2026-19654.patch | 52 +++
.../rsyslog/rsyslog_8.2402.0.bb | 2 +
.../hdf5/files/CVE-2026-17572.patch | 272 +++++++++++++
meta-oe/recipes-support/hdf5/hdf5_1.14.4-3.bb | 1 +
...-build-decide-if-drm_fb_helper_alloc.patch | 54 +++
.../vboxguestdrivers_7.0.14.bb | 9 +-
.../python/python3-beautifulsoup4_4.12.3.bb | 2 +-
.../python/python3-colorzero_2.0.bb | 2 +-
.../python/python3-flask-login_0.6.3.bb | 2 +-
.../python/python3-flask-mail_0.9.1.bb | 2 +-
.../python/python3-flask-user_0.6.19.bb | 2 +-
.../python3-pillow/CVE-2026-42311.patch | 356 ++++++++++++++++++
.../python3-pillow/CVE-2026-59198.patch | 60 +++
.../python3-pillow/CVE-2026-59204.patch | 37 ++
.../python/python3-pillow_10.3.0.bb | 3 +
.../python/python3-pyexpect_1.0.22.bb | 2 +-
31 files changed, 1257 insertions(+), 302 deletions(-)
create mode 100644 meta-networking/recipes-daemons/postfix/files/0001-makedefs-Account-for-linux-7.x-version.patch
delete mode 100644 meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2025-11677.patch
delete mode 100644 meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2025-11678.patch
create mode 100644 meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2026-19773.patch
rename meta-oe/recipes-connectivity/libwebsockets/{libwebsockets_4.3.3.bb => libwebsockets_4.3.10.bb} (94%)
create mode 100644 meta-oe/recipes-devtools/msgpack/msgpack-c/CVE-2026-72854.patch
rename meta-oe/recipes-devtools/php/{php_8.2.33.bb => php_8.2.34.bb} (99%)
create mode 100644 meta-oe/recipes-extended/polkit/files/CVE-2026-4897-01.patch
create mode 100644 meta-oe/recipes-extended/polkit/files/CVE-2026-4897-02.patch
create mode 100644 meta-oe/recipes-extended/polkit/files/CVE-2026-85498.patch
create mode 100644 meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654-regression.patch
create mode 100644 meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654.patch
create mode 100644 meta-oe/recipes-support/hdf5/files/CVE-2026-17572.patch
create mode 100644 meta-oe/recipes-support/vboxguestdrivers/vboxguestdrivers/0001-vboxvideo-let-the-build-decide-if-drm_fb_helper_alloc.patch
create mode 100644 meta-python/recipes-devtools/python/python3-pillow/CVE-2026-42311.patch
create mode 100644 meta-python/recipes-devtools/python/python3-pillow/CVE-2026-59198.patch
create mode 100644 meta-python/recipes-devtools/python/python3-pillow/CVE-2026-59204.patch
--
2.55.0
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [oe] [PATCH 00/14] Scarthgap pull request
2026-09-30 14:06 [PATCH 00/14] Scarthgap pull request Anuj Mittal
@ 2026-10-01 2:13 ` Khem Raj
0 siblings, 0 replies; 3+ messages in thread
From: Khem Raj @ 2026-10-01 2:13 UTC (permalink / raw)
To: anuj.mittal; +Cc: openembedded-devel
[-- Attachment #1: Type: text/plain, Size: 6004 bytes --]
Merged now, thanks Anuj
On Wed, Sep 30, 2026 at 7:06 AM Anuj Mittal via lists.openembedded.org
<anuj.mittal=oss.qualcomm.com@lists.openembedded.org> wrote:
> Please review and merge these changes in scarthgap. Tested on autobuilder
> and locally:
>
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/81/builds/1836
>
> The following changes since commit
> b5874ea07d69919d9b40d59f2c2f0bbd24bc3259:
>
> libssh: Fix CVE-2026-59850 (2026-09-02 10:39:59 +0530)
>
> are available in the Git repository at:
>
> https://git.openembedded.org/meta-openembedded-contrib anujm/scarthgap
>
> https://git.openembedded.org/meta-openembedded-contrib/log/?h=anujm/scarthgap
>
> for you to fetch changes up to 0f00f8b9a21950640da8c5707343e5540133f86e:
>
> vboxguestdrivers: fix vboxvideo build on kernels lacking
> drm_fb_helper_alloc_info (2026-09-29 16:10:23 +0530)
>
> ----------------------------------------------------------------
>
> Anuj Mittal (1):
> vboxguestdrivers: fix vboxvideo build on kernels lacking
> drm_fb_helper_alloc_info
>
> Benjamin Robin (Schneider Electric) (2):
> libwebsockets: update to version 4.3.10
> libwebsockets: fix CVE-2026-19773
>
> Deepak Rathore (1):
> rsyslog: Fix CVE-2026-19654
>
> Himani Ramesh Barde (1):
> postfix: fix build on hosts with Linux 7.x kernel
>
> Hitendra Prajapati (1):
> python3-pillow: fix CVE-2026-42311
>
> Jason Schonberg (1):
> php: upgrade 8.2.33 -> 8.2.34
>
> Peter Marko (3):
> msgpack-c: patch CVE-2026-72854
> recipes: correct homepage
> polkit: patch CVE-2026-4897 and CVE-2026-85498
>
> Rohini Sangam (2):
> python3-pillow: Security fix for CVE-2026-59198
> python3-pillow: Security fix for CVE-2026-59204
>
> Viswanath Kraleti (1):
> libfastjson: switch git branch from master to main
>
> Yogita Urade (1):
> hdf5: Fix CVE-2026-17572
>
> ...kedefs-Account-for-linux-7.x-version.patch | 47 +++
> .../recipes-daemons/postfix/postfix_3.8.19.bb | 1 +
> .../libwebsockets/CVE-2025-11677.patch | 161 --------
> .../libwebsockets/CVE-2025-11678.patch | 128 -------
> .../libwebsockets/CVE-2026-19773.patch | 32 ++
> ...ckets_4.3.3.bb => libwebsockets_4.3.10.bb} | 7 +-
> .../msgpack/msgpack-c/CVE-2026-72854.patch | 127 +++++++
> .../msgpack/msgpack-c_6.0.0.bb | 1 +
> .../php/{php_8.2.33.bb => php_8.2.34.bb} | 2 +-
> .../polkit/files/CVE-2026-4897-01.patch | 64 ++++
> .../polkit/files/CVE-2026-4897-02.patch | 32 ++
> .../polkit/files/CVE-2026-85498.patch | 38 ++
> meta-oe/recipes-extended/polkit/polkit_124.bb | 3 +
> .../rsyslog/libfastjson_1.2304.0.bb | 2 +-
> .../rsyslog/CVE-2026-19654-regression.patch | 56 +++
> .../rsyslog/rsyslog/CVE-2026-19654.patch | 52 +++
> .../rsyslog/rsyslog_8.2402.0.bb | 2 +
> .../hdf5/files/CVE-2026-17572.patch | 272 +++++++++++++
> meta-oe/recipes-support/hdf5/hdf5_1.14.4-3.bb | 1 +
> ...-build-decide-if-drm_fb_helper_alloc.patch | 54 +++
> .../vboxguestdrivers_7.0.14.bb | 9 +-
> .../python/python3-beautifulsoup4_4.12.3.bb | 2 +-
> .../python/python3-colorzero_2.0.bb | 2 +-
> .../python/python3-flask-login_0.6.3.bb | 2 +-
> .../python/python3-flask-mail_0.9.1.bb | 2 +-
> .../python/python3-flask-user_0.6.19.bb | 2 +-
> .../python3-pillow/CVE-2026-42311.patch | 356 ++++++++++++++++++
> .../python3-pillow/CVE-2026-59198.patch | 60 +++
> .../python3-pillow/CVE-2026-59204.patch | 37 ++
> .../python/python3-pillow_10.3.0.bb | 3 +
> .../python/python3-pyexpect_1.0.22.bb | 2 +-
> 31 files changed, 1257 insertions(+), 302 deletions(-)
> create mode 100644
> meta-networking/recipes-daemons/postfix/files/0001-makedefs-Account-for-linux-7.x-version.patch
> delete mode 100644
> meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2025-11677.patch
> delete mode 100644
> meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2025-11678.patch
> create mode 100644
> meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2026-19773.patch
> rename meta-oe/recipes-connectivity/libwebsockets/{libwebsockets_4.3.3.bb
> => libwebsockets_4.3.10.bb} (94%)
> create mode 100644
> meta-oe/recipes-devtools/msgpack/msgpack-c/CVE-2026-72854.patch
> rename meta-oe/recipes-devtools/php/{php_8.2.33.bb => php_8.2.34.bb}
> (99%)
> create mode 100644
> meta-oe/recipes-extended/polkit/files/CVE-2026-4897-01.patch
> create mode 100644
> meta-oe/recipes-extended/polkit/files/CVE-2026-4897-02.patch
> create mode 100644
> meta-oe/recipes-extended/polkit/files/CVE-2026-85498.patch
> create mode 100644
> meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654-regression.patch
> create mode 100644
> meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654.patch
> create mode 100644 meta-oe/recipes-support/hdf5/files/CVE-2026-17572.patch
> create mode 100644
> meta-oe/recipes-support/vboxguestdrivers/vboxguestdrivers/0001-vboxvideo-let-the-build-decide-if-drm_fb_helper_alloc.patch
> create mode 100644
> meta-python/recipes-devtools/python/python3-pillow/CVE-2026-42311.patch
> create mode 100644
> meta-python/recipes-devtools/python/python3-pillow/CVE-2026-59198.patch
> create mode 100644
> meta-python/recipes-devtools/python/python3-pillow/CVE-2026-59204.patch
>
> --
> 2.55.0
>
>
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#130524):
> https://lists.openembedded.org/g/openembedded-devel/message/130524
> Mute This Topic: https://lists.openembedded.org/mt/121508685/1997914
> Group Owner: openembedded-devel+owner@lists.openembedded.org
> Unsubscribe: https://lists.openembedded.org/g/openembedded-devel/unsub [
> raj.khem@gmail.com]
> -=-=-=-=-=-=-=-=-=-=-=-
>
>
[-- Attachment #2: Type: text/html, Size: 9270 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 00/14] Scarthgap pull request
@ 2026-07-17 23:26 Anuj Mittal
0 siblings, 0 replies; 3+ messages in thread
From: Anuj Mittal @ 2026-07-17 23:26 UTC (permalink / raw)
To: openembedded-devel
Please merge these changes in scarthgap. Tested locally and on autobuilder.
https://autobuilder.yoctoproject.org/valkyrie/#/builders/81/builds/1637
The following changes since commit 29a044218285fdc7fcdd63d5f0929cb3a27b6fed:
python3-matplotlib: fix build (2026-07-02 15:08:44 +0530)
are available in the Git repository at:
https://git.openembedded.org/meta-openembedded-contrib anujm/scarthgap
https://git.openembedded.org/meta-openembedded-contrib/log/?h=anujm/scarthgap
for you to fetch changes up to 7eb94107580092f79ff1b639a87762fe6f96aa12:
nginx: fix CVE-2026-42055 (2026-07-16 15:49:44 +0530)
----------------------------------------------------------------
Ashishkumar Parmar (2):
samba: Fix CVE-2026-3012
samba: Fix CVE-2026-4408
Benjamin Robin (Schneider Electric) (2):
dnsmasq: fix CVE-2026-2291
nginx: fix CVE-2026-42055
Deepak Rathore (4):
lldpd: Fix CVE-2026-46433
mbedtls: set CVE_STATUS for CVE-2025-66442
nmap: fix CVE-2026-58058
libidn: fix CVE-2026-57053
Esa Jaaskela (1):
uutils-coreutils: fix buildpaths QA warning
Etienne Cordonnier (1):
uutils-coreutils: disable stdbuf compilation
Jason Schonberg (1):
php: upgrade 8.2.31 -> 8.2.32
Roland Kovacs (1):
radvd: fix CVE-2026-48715
Sudhir Dumbhare (1):
mariadb: upgrade 10.11.16 -> 10.11.18
Yunseong Kim (1):
libyang: Fix CVE-2026-41401 and CVE-2026-44673
.../mbedtls/mbedtls_3.6.6.bb | 17 +
.../samba/samba/CVE-2026-3012_p1.patch | 131 ++
.../samba/samba/CVE-2026-3012_p2.patch | 51 +
.../samba/samba/CVE-2026-4408_p1.patch | 75 ++
.../samba/samba/CVE-2026-4408_p10.patch | 339 +++++
.../samba/samba/CVE-2026-4408_p11.patch | 94 ++
.../samba/samba/CVE-2026-4408_p12.patch | 47 +
.../samba/samba/CVE-2026-4408_p13.patch | 174 +++
.../samba/samba/CVE-2026-4408_p14.patch | 59 +
.../samba/samba/CVE-2026-4408_p15.patch | 1108 +++++++++++++++++
.../samba/samba/CVE-2026-4408_p16.patch | 422 +++++++
.../samba/samba/CVE-2026-4408_p17.patch | 55 +
.../samba/samba/CVE-2026-4408_p18.patch | 52 +
.../samba/samba/CVE-2026-4408_p2.patch | 133 ++
.../samba/samba/CVE-2026-4408_p3.patch | 208 ++++
.../samba/samba/CVE-2026-4408_p4.patch | 179 +++
.../samba/samba/CVE-2026-4408_p5.patch | 46 +
.../samba/samba/CVE-2026-4408_p6.patch | 131 ++
.../samba/samba/CVE-2026-4408_p7.patch | 84 ++
.../samba/samba/CVE-2026-4408_p8.patch | 39 +
.../samba/samba/CVE-2026-4408_p9.patch | 61 +
.../samba/samba_4.19.9.bb | 20 +
.../lldpd/files/CVE-2026-46433.patch | 36 +
.../recipes-daemons/lldpd/lldpd_1.0.18.bb | 1 +
.../radvd/files/CVE-2026-48715.patch | 213 ++++
.../radvd/files/CVE-2026-48715_dep.patch | 106 ++
.../recipes-daemons/radvd/radvd_2.19.bb | 2 +
.../recipes-support/dnsmasq/dnsmasq_2.90.bb | 1 +
.../dnsmasq/files/CVE-2026-2291.patch | 40 +
.../files/0002-do-not-compile-stdbuf.patch | 39 +
.../uutils-coreutils_0.0.28.bb | 5 +-
...10.11.16.bb => mariadb-native_10.11.18.bb} | 0
meta-oe/recipes-dbs/mysql/mariadb.inc | 2 +-
...ariadb_10.11.16.bb => mariadb_10.11.18.bb} | 0
.../php/{php_8.2.31.bb => php_8.2.32.bb} | 2 +-
.../libidn/libidn/CVE-2026-57053.patch | 28 +
.../recipes-extended/libidn/libidn_1.41.bb | 1 +
.../libyang/libyang/CVE-2026-41401.patch | 49 +
.../libyang/libyang/CVE-2026-44673.patch | 66 +
.../libyang/libyang_2.1.148.bb | 2 +
.../nmap/files/CVE-2026-58058.patch | 33 +
meta-oe/recipes-security/nmap/nmap_7.80.bb | 1 +
.../nginx/files/CVE-2026-42055.patch | 102 ++
.../recipes-httpd/nginx/nginx_1.24.0.bb | 1 +
44 files changed, 4252 insertions(+), 3 deletions(-)
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-3012_p1.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-3012_p2.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p1.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p10.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p11.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p12.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p13.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p14.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p15.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p16.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p17.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p18.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p2.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p3.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p4.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p5.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p6.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p7.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p8.patch
create mode 100644 meta-networking/recipes-connectivity/samba/samba/CVE-2026-4408_p9.patch
create mode 100644 meta-networking/recipes-daemons/lldpd/files/CVE-2026-46433.patch
create mode 100644 meta-networking/recipes-daemons/radvd/files/CVE-2026-48715.patch
create mode 100644 meta-networking/recipes-daemons/radvd/files/CVE-2026-48715_dep.patch
create mode 100644 meta-networking/recipes-support/dnsmasq/files/CVE-2026-2291.patch
create mode 100644 meta-oe/recipes-core/uutils-coreutils/files/0002-do-not-compile-stdbuf.patch
rename meta-oe/recipes-dbs/mysql/{mariadb-native_10.11.16.bb => mariadb-native_10.11.18.bb} (100%)
rename meta-oe/recipes-dbs/mysql/{mariadb_10.11.16.bb => mariadb_10.11.18.bb} (100%)
rename meta-oe/recipes-devtools/php/{php_8.2.31.bb => php_8.2.32.bb} (99%)
create mode 100644 meta-oe/recipes-extended/libidn/libidn/CVE-2026-57053.patch
create mode 100644 meta-oe/recipes-extended/libyang/libyang/CVE-2026-41401.patch
create mode 100644 meta-oe/recipes-extended/libyang/libyang/CVE-2026-44673.patch
create mode 100644 meta-oe/recipes-security/nmap/files/CVE-2026-58058.patch
create mode 100644 meta-webserver/recipes-httpd/nginx/files/CVE-2026-42055.patch
--
2.54.0
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-01 2:13 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 14:06 [PATCH 00/14] Scarthgap pull request Anuj Mittal
2026-10-01 2:13 ` [oe] " Khem Raj
-- strict thread matches above, loose matches on Subject: below --
2026-07-17 23:26 Anuj Mittal
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.