Openembedded Core Discussions
 help / color / mirror / Atom feed
From: Yoann Congal <yoann.congal@smile.fr>
To: openembedded-core@lists.openembedded.org
Cc: Paul Barker <paul@pbarker.dev>,
	Richard Purdie <richard.purdie@linuxfoundation.org>
Subject: [OE-core][scarthgap 00/27] Pull request (cover letter only)
Date: Fri,  4 Sep 2026 10:22:40 +0200	[thread overview]
Message-ID: <cover.1788510042.git.yoann.congal@smile.fr> (raw)

Those are the patches from the last patch review:
https://lore.kernel.org/all/cover.1788326578.git.yoann.congal@smile.fr/
(no review, no change)

Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/4636

The following changes since commit 310eec2cb646d7d1a3ca99bad7e37495bb418a0d:

  build-appliance-image: Update to scarthgap head revision (2026-08-28 09:52:39 +0100)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-next
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-next

for you to fetch changes up to 1b1e13055b4eed838e1411d91dea46de08e1d72f:

  patch: Fix CVE-2026-56288 (2026-09-01 17:07:13 +0200)

----------------------------------------------------------------

Emily Vekariya (2):
  python3-pyasn1: Fix CVE-2026-59886
  python3-pyasn1: Fix CVE-2026-59884

Hemanth Kumar M D (1):
  glibc: fix CVE-2026-5435

Hetvi Thakar (5):
  wget: Fix CVE-2026-58469
  wget: Fix CVE-2026-58471
  wget: Fix CVE-2026-58472
  patch: Fix CVE-2026-56289
  patch: Fix CVE-2026-56288

Jaipaul Cheernam (4):
  systemd: Fix CVE-2026-29111
  perl: fix CVE-2026-13221
  perl: fix CVE-2026-57432
  perl: fix CVE-2025-40909

Martin Jansa (1):
  socat: fix native build on host with newer glibc

Peter Marko (5):
  python3: upgrade 3.12.13 -> 3.12.14
  systemd: upgrade 255.21 -> 255.22
  libarchive: handle CVE-2026-5121
  libarchive: patch CVE-2026-5745
  gnutls: set status for CVE-2026-1584

Siddharth Doshi (9):
  vim: Security Fix for CVE-2026-55693
  vim: Security Fix for CVE-2026-55892
  vim: Security Fix for CVE-2026-55895
  vim: Security Fix for CVE-2026-57452
  vim: Security Fix for CVE-2026-57455
  vim: Security Fix for CVE-2026-59856
  vim: Security Fix for CVE-2026-59857
  vim: Security Fix for CVE-2026-59858
  vim: Security Fix for CVE-2026-57456

 ...ixed-strchr-with-const-for-new-glibc.patch |   38 +
 .../socat/socat_1.8.0.0.bb                    |    1 +
 .../glibc/glibc/0024-CVE-2026-5435.patch      |  137 ++
 meta/recipes-core/glibc/glibc_2.39.bb         |    1 +
 ...55.21.bb => systemd-boot-native_255.22.bb} |    0
 ...-boot_255.21.bb => systemd-boot_255.22.bb} |    0
 meta/recipes-core/systemd/systemd.inc         |    2 +-
 .../systemd/systemd/CVE-2026-29111-01.patch   |  170 +++
 .../systemd/systemd/CVE-2026-29111-02.patch   |   85 ++
 .../systemd/systemd/CVE-2026-29111-03.patch   |  106 ++
 .../systemd/systemd/CVE-2026-29111-04.patch   |   35 +
 .../{systemd_255.21.bb => systemd_255.22.bb}  |    4 +
 .../patch/patch/CVE-2026-56288.patch          |   75 +
 .../patch/patch/CVE-2026-56289.patch          |   36 +
 meta/recipes-devtools/patch/patch_2.7.6.bb    |    2 +
 .../perl-cross/files/CVE-2025-40909-dep.patch |   25 +
 .../perl-cross/perlcross_1.6.2.bb             |    1 +
 .../perl/files/CVE-2025-40909.patch           |  412 ++++++
 .../perl/files/CVE-2026-13221.patch           |   75 +
 .../perl/files/CVE-2026-57432-01.patch        |   52 +
 .../perl/files/CVE-2026-57432-02.patch        |   34 +
 meta/recipes-devtools/perl/perl_5.38.4.bb     |    4 +
 .../recipes-devtools/python/python-pyasn1.inc |    2 +
 .../python3-pyasn1/CVE-2026-59884.patch       |  245 ++++
 .../python3-pyasn1/CVE-2026-59886.patch       |  252 ++++
 ...shebang-overflow-on-python-config.py.patch |    2 +-
 ...-qemu-wrapper-when-gathering-profile.patch |    2 +-
 ...e-treat-overflow-in-UID-GID-as-failu.patch |    2 +-
 .../python/python3/CVE-2025-13462.patch       |  142 --
 .../python/python3/CVE-2026-11940.patch       |   66 -
 .../python/python3/CVE-2026-11972.patch       |   60 -
 .../python/python3/CVE-2026-1502.patch        |  113 --
 .../python3/CVE-2026-3644_CVE-2026-0672.patch |  154 --
 .../python/python3/CVE-2026-4224.patch        |  121 --
 .../python3/CVE-2026-4519_CVE-2026-4786.patch |   66 -
 .../python/python3/CVE-2026-4519_p1.patch     |  107 --
 .../python/python3/CVE-2026-4519_p2.patch     |  159 ---
 .../python/python3/CVE-2026-6100.patch        |   75 -
 .../python/python3/CVE-2026-7210.patch        |  148 --
 .../python/python3/CVE-2026-9669.patch        |   96 --
 .../python/python3/makerace.patch             |    2 +-
 ...{python3_3.12.13.bb => python3_3.12.14.bb} |   24 +-
 ...atch => CVE-2026-4426_CVE-2026-5121.patch} |    1 +
 .../libarchive/CVE-2026-5121-02.patch         | 1270 +++++++++++++++++
 .../libarchive/libarchive/CVE-2026-5745.patch |   39 +
 .../libarchive/libarchive_3.7.9.bb            |    4 +-
 .../wget/CVE-2026-58469-regression_p1.patch   |   39 +
 .../wget/CVE-2026-58469-regression_p2.patch   |   26 +
 .../wget/wget/CVE-2026-58469.patch            |   53 +
 .../wget/wget/CVE-2026-58471.patch            |   71 +
 .../wget/wget/CVE-2026-58472-regression.patch |  236 +++
 .../wget/wget/CVE-2026-58472.patch            |   77 +
 meta/recipes-extended/wget/wget_1.21.4.bb     |    6 +
 meta/recipes-support/gnutls/gnutls_3.8.4.bb   |    1 +
 .../vim/files/CVE-2026-55693.patch            |   88 ++
 .../vim/files/CVE-2026-55892.patch            |   81 ++
 .../vim/files/CVE-2026-55895.patch            |   53 +
 .../vim/files/CVE-2026-57452.patch            |   76 +
 .../vim/files/CVE-2026-57455.patch            |   72 +
 .../vim/files/CVE-2026-57456.patch            |   90 ++
 .../vim/files/CVE-2026-59856.patch            |  103 ++
 .../vim/files/CVE-2026-59857.patch            |  110 ++
 .../vim/files/CVE-2026-59858.patch            |  134 ++
 meta/recipes-support/vim/vim.inc              |    9 +
 64 files changed, 4444 insertions(+), 1328 deletions(-)
 create mode 100644 meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch
 create mode 100644 meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch
 rename meta/recipes-core/systemd/{systemd-boot-native_255.21.bb => systemd-boot-native_255.22.bb} (100%)
 rename meta/recipes-core/systemd/{systemd-boot_255.21.bb => systemd-boot_255.22.bb} (100%)
 create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch
 create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch
 create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch
 create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch
 rename meta/recipes-core/systemd/{systemd_255.21.bb => systemd_255.22.bb} (99%)
 create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56288.patch
 create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56289.patch
 create mode 100644 meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2025-40909.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
 create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch
 create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2025-13462.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11940.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11972.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-1502.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4224.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-6100.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-7210.patch
 delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-9669.patch
 rename meta/recipes-devtools/python/{python3_3.12.13.bb => python3_3.12.14.bb} (96%)
 rename meta/recipes-extended/libarchive/libarchive/{CVE-2026-4426.patch => CVE-2026-4426_CVE-2026-5121.patch} (99%)
 create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch
 create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58471.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-55693.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-55895.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-57456.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-59856.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-59857.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch



             reply	other threads:[~2026-09-04  8:23 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-04  8:22 Yoann Congal [this message]
  -- strict thread matches above, loose matches on Subject: below --
2026-02-12 13:27 [OE-core][scarthgap 00/27] Pull request (cover letter only) Yoann Congal
2026-02-13  8:51 ` Paul Barker

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cover.1788510042.git.yoann.congal@smile.fr \
    --to=yoann.congal@smile.fr \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=paul@pbarker.dev \
    --cc=richard.purdie@linuxfoundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox