From: "sateesh m" <sateesh0457@gmail.com>
To: yocto@lists.yoctoproject.org
Subject: mozjs 60.9 CVE issues fix.
Date: Wed, 14 May 2025 21:34:03 -0700 [thread overview]
Message-ID: <yoeb.1747283643576382007.FPXh@lists.yoctoproject.org> (raw)
[-- Attachment #1: Type: text/plain, Size: 1276 bytes --]
Hi Team,
I am currently working on CVE-related issues in the mozjs library that need to be fixed for version 60.9. I am using the Dunfell branch, but upon comparing it to the Gatesgarth branch, I noticed an additional patch is available. The patch file://0014-fallback-to-2011-C++-standard.patch has been removed, and 0014-remove-JS_VOLATIME_ARM.patch has been added instead.
Could you confirm whether these changes need to be applied to my local build as well? Additionally, I would like to understand the reason for removing the fallback-to-2011 patch. If we retain it, could it lead to any issues?
I want to incorporate upstream patch changes related to the mozjs library. Since version 60.9 is a tar bundle and not a Git source, where can I find relevant solutions and reference links? I have reviewed Bugzilla IDs, and they indicate that the issue has been fixed in example Firefox ESR78 and ESR128 and few mentioned <91 (Is that mean below 91 all versions may effect changes). However, based on my understanding, adding those changes might result in dependency package version issues, such as requiring a more recent Python version (e.g., Python 3.10).
I would appreciate any clarification on this matter.
Thanks in advance.
Best regards,
Satish M
[-- Attachment #2: Type: text/html, Size: 1467 bytes --]
next reply other threads:[~2025-05-15 4:34 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-15 4:34 sateesh m [this message]
2025-05-15 6:52 ` [yocto] mozjs 60.9 CVE issues fix Gyorgy Sarvari
2025-05-15 8:30 ` sateesh m
2025-05-15 10:49 ` Gyorgy Sarvari
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=yoeb.1747283643576382007.FPXh@lists.yoctoproject.org \
--to=sateesh0457@gmail.com \
--cc=yocto@lists.yoctoproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.