From: "Marko, Peter" <Peter.Marko@siemens.com>
To: "vanusuri@mvista.com" <vanusuri@mvista.com>,
"openembedded-core@lists.openembedded.org"
<openembedded-core@lists.openembedded.org>
Subject: RE: [OE-core][scarthgap][patch] gnupg: upgrade 2.4.8 -> 2.4.9
Date: Mon, 12 Jan 2026 07:17:52 +0000 [thread overview]
Message-ID: <AS1PR10MB56973C8003890BF9FDACAF5AFD81A@AS1PR10MB5697.EURPRD10.PROD.OUTLOOK.COM> (raw)
In-Reply-To: <20260112071440.2411292-1-vanusuri@mvista.com>
Sent already 2 days ago...
https://lists.openembedded.org/g/openembedded-core/message/229168
Peter
-----Original Message-----
From: openembedded-core@lists.openembedded.org <openembedded-core@lists.openembedded.org> On Behalf Of Vijay Anusuri via lists.openembedded.org
Sent: Monday, January 12, 2026 8:15
To: openembedded-core@lists.openembedded.org
Cc: Vijay Anusuri <vanusuri@mvista.com>
Subject: [OE-core][scarthgap][patch] gnupg: upgrade 2.4.8 -> 2.4.9
This release includes fix for CVE-2025-68973
Changelog:
==========
* gpg: Fix possible memory corruption in the armor parser. [T7906]
* gpg: Avoid potential downgrade to SHA1 in 3rd party key
signatures. [rGddb012be7f]
* gpg: Error out on unverified output for non-detached signatures.
[rG9d302f978b]
* gpg: Do not allow compressed key packets on import. [T7014]
* scd: Fix a harmless read buffer over-read in a function used by
PKCS#15 cards. [T7662]
* dirmngr: Do not require a keyserver for "gpg --fetch-key".
[T7693]
* agent: Fix ssh-agent's request_identities for skipped Brainpool
keys. [rG6bf5696c85]
Release-info: https://dev.gnupg.org/T8001
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
meta/recipes-support/gnupg/{gnupg_2.4.8.bb => gnupg_2.4.9.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-support/gnupg/{gnupg_2.4.8.bb => gnupg_2.4.9.bb} (97%)
diff --git a/meta/recipes-support/gnupg/gnupg_2.4.8.bb b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
similarity index 97%
rename from meta/recipes-support/gnupg/gnupg_2.4.8.bb
rename to meta/recipes-support/gnupg/gnupg_2.4.9.bb
index a6e777abf8..4f60a4e7b2 100644
--- a/meta/recipes-support/gnupg/gnupg_2.4.8.bb
+++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
@@ -23,7 +23,7 @@ SRC_URI:append:class-native = " file://0001-configure.ac-use-a-custom-value-for-
file://relocate.patch"
SRC_URI:append:class-nativesdk = " file://relocate.patch"
-SRC_URI[sha256sum] = "b58c80d79b04d3243ff49c1c3fc6b5f83138eb3784689563bcdd060595318616"
+SRC_URI[sha256sum] = "dd17ab2e9a04fd79d39d853f599cbc852062ddb9ab52a4ddeb4176fd8b302964"
EXTRA_OECONF = "--disable-ldap \
--disable-ccid-driver \
--
2.43.0
next prev parent reply other threads:[~2026-01-12 7:18 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-01-12 7:14 [OE-core][scarthgap][patch] gnupg: upgrade 2.4.8 -> 2.4.9 Vijay Anusuri
2026-01-12 7:17 ` Marko, Peter [this message]
2026-01-12 7:29 ` Vijay Anusuri
2026-01-12 18:21 ` Yoann Congal
[not found] <1889800F45802F27.2902090@lists.openembedded.org>
2026-02-04 7:20 ` [OE-core][scarthgap][PATCH] " Marko, Peter
2026-02-04 8:11 ` Yoann Congal
-- strict thread matches above, loose matches on Subject: below --
2026-01-10 22:44 Peter Marko
2026-02-04 10:10 ` Yoann Congal
2026-02-18 21:28 ` Marko, Peter
2026-02-19 13:54 ` Yoann Congal
2026-02-22 20:53 ` Marko, Peter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=AS1PR10MB56973C8003890BF9FDACAF5AFD81A@AS1PR10MB5697.EURPRD10.PROD.OUTLOOK.COM \
--to=peter.marko@siemens.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=vanusuri@mvista.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox