* [OE-core][scarthgap 00/27] Pull request (cover letter only)
@ 2026-09-04 8:22 Yoann Congal
0 siblings, 0 replies; 3+ messages in thread
From: Yoann Congal @ 2026-09-04 8:22 UTC (permalink / raw)
To: openembedded-core; +Cc: Paul Barker, Richard Purdie
Those are the patches from the last patch review:
https://lore.kernel.org/all/cover.1788326578.git.yoann.congal@smile.fr/
(no review, no change)
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/4636
The following changes since commit 310eec2cb646d7d1a3ca99bad7e37495bb418a0d:
build-appliance-image: Update to scarthgap head revision (2026-08-28 09:52:39 +0100)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-next
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-next
for you to fetch changes up to 1b1e13055b4eed838e1411d91dea46de08e1d72f:
patch: Fix CVE-2026-56288 (2026-09-01 17:07:13 +0200)
----------------------------------------------------------------
Emily Vekariya (2):
python3-pyasn1: Fix CVE-2026-59886
python3-pyasn1: Fix CVE-2026-59884
Hemanth Kumar M D (1):
glibc: fix CVE-2026-5435
Hetvi Thakar (5):
wget: Fix CVE-2026-58469
wget: Fix CVE-2026-58471
wget: Fix CVE-2026-58472
patch: Fix CVE-2026-56289
patch: Fix CVE-2026-56288
Jaipaul Cheernam (4):
systemd: Fix CVE-2026-29111
perl: fix CVE-2026-13221
perl: fix CVE-2026-57432
perl: fix CVE-2025-40909
Martin Jansa (1):
socat: fix native build on host with newer glibc
Peter Marko (5):
python3: upgrade 3.12.13 -> 3.12.14
systemd: upgrade 255.21 -> 255.22
libarchive: handle CVE-2026-5121
libarchive: patch CVE-2026-5745
gnutls: set status for CVE-2026-1584
Siddharth Doshi (9):
vim: Security Fix for CVE-2026-55693
vim: Security Fix for CVE-2026-55892
vim: Security Fix for CVE-2026-55895
vim: Security Fix for CVE-2026-57452
vim: Security Fix for CVE-2026-57455
vim: Security Fix for CVE-2026-59856
vim: Security Fix for CVE-2026-59857
vim: Security Fix for CVE-2026-59858
vim: Security Fix for CVE-2026-57456
...ixed-strchr-with-const-for-new-glibc.patch | 38 +
.../socat/socat_1.8.0.0.bb | 1 +
.../glibc/glibc/0024-CVE-2026-5435.patch | 137 ++
meta/recipes-core/glibc/glibc_2.39.bb | 1 +
...55.21.bb => systemd-boot-native_255.22.bb} | 0
...-boot_255.21.bb => systemd-boot_255.22.bb} | 0
meta/recipes-core/systemd/systemd.inc | 2 +-
.../systemd/systemd/CVE-2026-29111-01.patch | 170 +++
.../systemd/systemd/CVE-2026-29111-02.patch | 85 ++
.../systemd/systemd/CVE-2026-29111-03.patch | 106 ++
.../systemd/systemd/CVE-2026-29111-04.patch | 35 +
.../{systemd_255.21.bb => systemd_255.22.bb} | 4 +
.../patch/patch/CVE-2026-56288.patch | 75 +
.../patch/patch/CVE-2026-56289.patch | 36 +
meta/recipes-devtools/patch/patch_2.7.6.bb | 2 +
.../perl-cross/files/CVE-2025-40909-dep.patch | 25 +
.../perl-cross/perlcross_1.6.2.bb | 1 +
.../perl/files/CVE-2025-40909.patch | 412 ++++++
.../perl/files/CVE-2026-13221.patch | 75 +
.../perl/files/CVE-2026-57432-01.patch | 52 +
.../perl/files/CVE-2026-57432-02.patch | 34 +
meta/recipes-devtools/perl/perl_5.38.4.bb | 4 +
.../recipes-devtools/python/python-pyasn1.inc | 2 +
.../python3-pyasn1/CVE-2026-59884.patch | 245 ++++
.../python3-pyasn1/CVE-2026-59886.patch | 252 ++++
...shebang-overflow-on-python-config.py.patch | 2 +-
...-qemu-wrapper-when-gathering-profile.patch | 2 +-
...e-treat-overflow-in-UID-GID-as-failu.patch | 2 +-
.../python/python3/CVE-2025-13462.patch | 142 --
.../python/python3/CVE-2026-11940.patch | 66 -
.../python/python3/CVE-2026-11972.patch | 60 -
.../python/python3/CVE-2026-1502.patch | 113 --
.../python3/CVE-2026-3644_CVE-2026-0672.patch | 154 --
.../python/python3/CVE-2026-4224.patch | 121 --
.../python3/CVE-2026-4519_CVE-2026-4786.patch | 66 -
.../python/python3/CVE-2026-4519_p1.patch | 107 --
.../python/python3/CVE-2026-4519_p2.patch | 159 ---
.../python/python3/CVE-2026-6100.patch | 75 -
.../python/python3/CVE-2026-7210.patch | 148 --
.../python/python3/CVE-2026-9669.patch | 96 --
.../python/python3/makerace.patch | 2 +-
...{python3_3.12.13.bb => python3_3.12.14.bb} | 24 +-
...atch => CVE-2026-4426_CVE-2026-5121.patch} | 1 +
.../libarchive/CVE-2026-5121-02.patch | 1270 +++++++++++++++++
.../libarchive/libarchive/CVE-2026-5745.patch | 39 +
.../libarchive/libarchive_3.7.9.bb | 4 +-
.../wget/CVE-2026-58469-regression_p1.patch | 39 +
.../wget/CVE-2026-58469-regression_p2.patch | 26 +
.../wget/wget/CVE-2026-58469.patch | 53 +
.../wget/wget/CVE-2026-58471.patch | 71 +
.../wget/wget/CVE-2026-58472-regression.patch | 236 +++
.../wget/wget/CVE-2026-58472.patch | 77 +
meta/recipes-extended/wget/wget_1.21.4.bb | 6 +
meta/recipes-support/gnutls/gnutls_3.8.4.bb | 1 +
.../vim/files/CVE-2026-55693.patch | 88 ++
.../vim/files/CVE-2026-55892.patch | 81 ++
.../vim/files/CVE-2026-55895.patch | 53 +
.../vim/files/CVE-2026-57452.patch | 76 +
.../vim/files/CVE-2026-57455.patch | 72 +
.../vim/files/CVE-2026-57456.patch | 90 ++
.../vim/files/CVE-2026-59856.patch | 103 ++
.../vim/files/CVE-2026-59857.patch | 110 ++
.../vim/files/CVE-2026-59858.patch | 134 ++
meta/recipes-support/vim/vim.inc | 9 +
64 files changed, 4444 insertions(+), 1328 deletions(-)
create mode 100644 meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch
create mode 100644 meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch
rename meta/recipes-core/systemd/{systemd-boot-native_255.21.bb => systemd-boot-native_255.22.bb} (100%)
rename meta/recipes-core/systemd/{systemd-boot_255.21.bb => systemd-boot_255.22.bb} (100%)
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch
rename meta/recipes-core/systemd/{systemd_255.21.bb => systemd_255.22.bb} (99%)
create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56288.patch
create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56289.patch
create mode 100644 meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2025-40909.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch
create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2025-13462.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11940.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11972.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-1502.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4224.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-6100.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-7210.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-9669.patch
rename meta/recipes-devtools/python/{python3_3.12.13.bb => python3_3.12.14.bb} (96%)
rename meta/recipes-extended/libarchive/libarchive/{CVE-2026-4426.patch => CVE-2026-4426_CVE-2026-5121.patch} (99%)
create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch
create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58471.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55693.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55895.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57456.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59856.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59857.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
^ permalink raw reply [flat|nested] 3+ messages in thread* [OE-core][scarthgap 00/27] Pull request (cover letter only)
@ 2026-02-12 13:27 Yoann Congal
2026-02-13 8:51 ` Paul Barker
0 siblings, 1 reply; 3+ messages in thread
From: Yoann Congal @ 2026-02-12 13:27 UTC (permalink / raw)
To: openembedded-core; +Cc: Paul Barker
Those are the patches from the last patch review:
https://lore.kernel.org/openembedded-core/cover.1770626074.git.yoann.congal@smile.fr/T/#t
with the following modification:
* zlib: ignore CVE-2026-22184 was changed to a cherry-pick from master
and needed commits backported:
* zlib: cleanup CVE_STATUS[CVE-2023-45853]
* zlib: Add CVE_PRODUCT to exclude false positives
Passed a-full on autobuilder (with AB-INT):
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/3195
* The build qemuarm-oecore failed:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/40/builds/3140
This was caused by bug #16143 – AB-INT: do_image_wic: tar command return exit status 2
* The build qemuarm-oecore was succesfully retried:
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/40/builds/3143
The following changes since commit d50e4680ed6f930582d907b37c9ed545a89f5c27:
build-appliance-image: Update to scarthgap head revision (2026-01-26 09:50:47 +0000)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-next
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-next
for you to fetch changes up to 5f81d44ce98b9bfe905acf162b01b1b80f00ac27:
libtheora: set CVE_PRODUCT (2026-02-10 16:40:35 +0100)
----------------------------------------------------------------
Adarsh Jagadish Kamini (1):
python-urllib3: Backport fix for CVE-2026-21441
Amaury Couderc (1):
curl: patch CVE-2025-14524
Ankur Tyagi (2):
ffmpeg: upgrade 6.1.3 -> 6.1.4
ffmpeg: ignore CVE-2025-25469
Benjamin Robin (Schneider Electric) (1):
meta/classes: fix missing vardeps for CVE status variables
Daniel Turull (1):
improve_kernel_cve_report: add script for postprocesing of kernel CVE
data
Fred Bacon (1):
lighttpd: Fix trailing slash on files in mod_dirlisting
Het Patel (1):
zlib: Add CVE_PRODUCT to exclude false positives
Hitendra Prajapati (1):
curl: fix CVE-2025-10148
Hugo SIMELIERE (1):
libtasn1: Fix CVE-2025-13151
Ken Kurematsu (1):
libtheora: set CVE_PRODUCT
Khai Dang (1):
docbook-xml-dtd4: fix the fetching failure
Peter Marko (12):
expat: patch CVE-2026-24515
expat: patch CVE-2026-25210
glib-2.0: patch CVE-2026-0988
libpng: patch CVE-2026-22695
libpng: patch CVE-2026-22801
libxml2: patch CVE-2026-0989
libxml2: patch CVE-2026-0990
libxml2: patch CVE-2026-0992
libxml2: add follow-up patch for CVE-2026-0992
python3: patch CVE-2025-13837
zlib: ignore CVE-2026-22184
glibc: stable 2.39 branch updates
Richard Purdie (1):
pseudo: Update to 1.9.3 release
Vijay Anusuri (1):
inetutils: Fix CVE-2026-24061
Yoann Congal (1):
zlib: cleanup CVE_STATUS[CVE-2023-45853]
meta/classes/create-spdx-2.2.bbclass | 1 +
meta/classes/create-spdx-3.0.bbclass | 2 +
meta/classes/cve-check.bbclass | 1 +
meta/classes/vex.bbclass | 1 +
.../inetutils/CVE-2026-24061-1.patch | 41 ++
.../inetutils/CVE-2026-24061-2.patch | 85 ++++
.../inetutils/inetutils_2.5.bb | 2 +
.../expat/expat/CVE-2026-24515-01.patch | 43 ++
.../expat/expat/CVE-2026-24515-02.patch | 117 +++++
.../expat/expat/CVE-2026-25210-01.patch | 27 +
.../expat/expat/CVE-2026-25210-02.patch | 38 ++
.../expat/expat/CVE-2026-25210-03.patch | 28 ++
meta/recipes-core/expat/expat_2.6.4.bb | 5 +
.../glib-2.0/glib-2.0/CVE-2026-0988.patch | 58 +++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
meta/recipes-core/glibc/glibc-version.inc | 2 +-
meta/recipes-core/glibc/glibc_2.39.bb | 2 +-
.../libxml/libxml2/CVE-2026-0989.patch | 309 ++++++++++++
.../libxml/libxml2/CVE-2026-0990.patch | 76 +++
.../libxml/libxml2/CVE-2026-0992-01.patch | 49 ++
.../libxml/libxml2/CVE-2026-0992-02.patch | 323 ++++++++++++
.../libxml/libxml2/CVE-2026-0992-03.patch | 33 ++
meta/recipes-core/libxml/libxml2_2.12.10.bb | 5 +
meta/recipes-core/zlib/zlib_1.3.1.bb | 6 +-
.../docbook-xml/docbook-xml-dtd4_4.5.bb | 10 +-
meta/recipes-devtools/pseudo/pseudo_git.bb | 4 +-
.../python3-urllib3/CVE-2026-21441.patch | 105 ++++
.../python/python3-urllib3_2.2.2.bb | 1 +
.../python/python3/CVE-2025-13837.patch | 162 ++++++
.../python/python3_3.12.12.bb | 1 +
.../lighttpd/0001-mod_dirlisting.patch | 48 ++
.../lighttpd/lighttpd_1.4.74.bb | 1 +
.../ffmpeg/ffmpeg/CVE-2024-35365.patch | 62 ---
.../ffmpeg/ffmpeg/CVE-2024-36618.patch | 36 --
.../ffmpeg/ffmpeg/CVE-2025-1594.patch | 105 ----
.../{ffmpeg_6.1.3.bb => ffmpeg_6.1.4.bb} | 7 +-
.../libpng/files/CVE-2026-22695.patch | 77 +++
.../libpng/files/CVE-2026-22801.patch | 173 +++++++
.../libpng/libpng_1.6.42.bb | 2 +
.../libtheora/libtheora_1.1.1.bb | 2 +
.../curl/curl/CVE-2025-10148.patch | 57 +++
.../curl/curl/CVE-2025-14524.patch | 44 ++
meta/recipes-support/curl/curl_8.7.1.bb | 2 +
.../gnutls/libtasn1/CVE-2025-13151.patch | 30 ++
.../recipes-support/gnutls/libtasn1_4.20.0.bb | 1 +
scripts/contrib/improve_kernel_cve_report.py | 467 ++++++++++++++++++
46 files changed, 2434 insertions(+), 218 deletions(-)
create mode 100644 meta/recipes-connectivity/inetutils/inetutils/CVE-2026-24061-1.patch
create mode 100644 meta/recipes-connectivity/inetutils/inetutils/CVE-2026-24061-2.patch
create mode 100644 meta/recipes-core/expat/expat/CVE-2026-24515-01.patch
create mode 100644 meta/recipes-core/expat/expat/CVE-2026-24515-02.patch
create mode 100644 meta/recipes-core/expat/expat/CVE-2026-25210-01.patch
create mode 100644 meta/recipes-core/expat/expat/CVE-2026-25210-02.patch
create mode 100644 meta/recipes-core/expat/expat/CVE-2026-25210-03.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-0988.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-0989.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-0990.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-0992-01.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-0992-02.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-0992-03.patch
create mode 100644 meta/recipes-devtools/python/python3-urllib3/CVE-2026-21441.patch
create mode 100644 meta/recipes-devtools/python/python3/CVE-2025-13837.patch
create mode 100644 meta/recipes-extended/lighttpd/lighttpd/0001-mod_dirlisting.patch
delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-35365.patch
delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-36618.patch
delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2025-1594.patch
rename meta/recipes-multimedia/ffmpeg/{ffmpeg_6.1.3.bb => ffmpeg_6.1.4.bb} (98%)
create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-22695.patch
create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-22801.patch
create mode 100644 meta/recipes-support/curl/curl/CVE-2025-10148.patch
create mode 100644 meta/recipes-support/curl/curl/CVE-2025-14524.patch
create mode 100644 meta/recipes-support/gnutls/libtasn1/CVE-2025-13151.patch
create mode 100755 scripts/contrib/improve_kernel_cve_report.py
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [OE-core][scarthgap 00/27] Pull request (cover letter only)
2026-02-12 13:27 Yoann Congal
@ 2026-02-13 8:51 ` Paul Barker
0 siblings, 0 replies; 3+ messages in thread
From: Paul Barker @ 2026-02-13 8:51 UTC (permalink / raw)
To: Yoann Congal, openembedded-core
[-- Attachment #1: Type: text/plain, Size: 8154 bytes --]
On Thu, 2026-02-12 at 14:27 +0100, Yoann Congal wrote:
> Those are the patches from the last patch review:
> https://lore.kernel.org/openembedded-core/cover.1770626074.git.yoann.congal@smile.fr/T/#t
> with the following modification:
> * zlib: ignore CVE-2026-22184 was changed to a cherry-pick from master
> and needed commits backported:
> * zlib: cleanup CVE_STATUS[CVE-2023-45853]
> * zlib: Add CVE_PRODUCT to exclude false positives
>
> Passed a-full on autobuilder (with AB-INT):
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/3195
> * The build qemuarm-oecore failed:
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/40/builds/3140
> This was caused by bug #16143 – AB-INT: do_image_wic: tar command return exit status 2
> * The build qemuarm-oecore was succesfully retried:
> https://autobuilder.yoctoproject.org/valkyrie/?#/builders/40/builds/3143
Hi Richard, Yoann,
We have an understanding of #16143 now, and this issue happening is not
a regression caused by any of the patches here, so I think this is good
to merge.
The following changes since commit d50e4680ed6f930582d907b37c9ed545a89f5c27:
build-appliance-image: Update to scarthgap head revision (2026-01-26 09:50:47 +0000)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib pbarker/scarthgap
for you to fetch changes up to e86e50b8c5b16065dcb35ebf4b00eff59c5da78c:
libtheora: set CVE_PRODUCT (2026-02-12 23:44:37 +0000)
----------------------------------------------------------------
Adarsh Jagadish Kamini (1):
python-urllib3: Backport fix for CVE-2026-21441
Amaury Couderc (1):
curl: patch CVE-2025-14524
Ankur Tyagi (2):
ffmpeg: upgrade 6.1.3 -> 6.1.4
ffmpeg: ignore CVE-2025-25469
Benjamin Robin (Schneider Electric) (1):
meta/classes: fix missing vardeps for CVE status variables
Daniel Turull (1):
improve_kernel_cve_report: add script for postprocesing of kernel CVE data
Fred Bacon (1):
lighttpd: Fix trailing slash on files in mod_dirlisting
Het Patel (1):
zlib: Add CVE_PRODUCT to exclude false positives
Hitendra Prajapati (1):
curl: fix CVE-2025-10148
Hugo SIMELIERE (1):
libtasn1: Fix CVE-2025-13151
Ken Kurematsu (1):
libtheora: set CVE_PRODUCT
Khai Dang (1):
docbook-xml-dtd4: fix the fetching failure
Peter Marko (12):
expat: patch CVE-2026-24515
expat: patch CVE-2026-25210
glib-2.0: patch CVE-2026-0988
libpng: patch CVE-2026-22695
libpng: patch CVE-2026-22801
libxml2: patch CVE-2026-0989
libxml2: patch CVE-2026-0990
libxml2: patch CVE-2026-0992
libxml2: add follow-up patch for CVE-2026-0992
python3: patch CVE-2025-13837
zlib: ignore CVE-2026-22184
glibc: stable 2.39 branch updates
Richard Purdie (1):
pseudo: Update to 1.9.3 release
Vijay Anusuri (1):
inetutils: Fix CVE-2026-24061
Yoann Congal (1):
zlib: cleanup CVE_STATUS[CVE-2023-45853]
meta/classes/create-spdx-2.2.bbclass | 1 +
meta/classes/create-spdx-3.0.bbclass | 2 +
meta/classes/cve-check.bbclass | 1 +
meta/classes/vex.bbclass | 1 +
.../inetutils/inetutils/CVE-2026-24061-1.patch | 41 ++
.../inetutils/inetutils/CVE-2026-24061-2.patch | 85 ++++
.../inetutils/inetutils_2.5.bb | 2 +
.../expat/expat/CVE-2026-24515-01.patch | 43 ++
.../expat/expat/CVE-2026-24515-02.patch | 117 ++++++
.../expat/expat/CVE-2026-25210-01.patch | 27 ++
.../expat/expat/CVE-2026-25210-02.patch | 38 ++
.../expat/expat/CVE-2026-25210-03.patch | 28 ++
meta/recipes-core/expat/expat_2.6.4.bb | 5 +
.../glib-2.0/glib-2.0/CVE-2026-0988.patch | 58 +++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
meta/recipes-core/glibc/glibc-version.inc | 2 +-
meta/recipes-core/glibc/glibc_2.39.bb | 2 +-
.../libxml/libxml2/CVE-2026-0989.patch | 309 ++++++++++++++
.../libxml/libxml2/CVE-2026-0990.patch | 76 ++++
.../libxml/libxml2/CVE-2026-0992-01.patch | 49 +++
.../libxml/libxml2/CVE-2026-0992-02.patch | 323 ++++++++++++++
.../libxml/libxml2/CVE-2026-0992-03.patch | 33 ++
meta/recipes-core/libxml/libxml2_2.12.10.bb | 5 +
meta/recipes-core/zlib/zlib_1.3.1.bb | 6 +-
.../docbook-xml/docbook-xml-dtd4_4.5.bb | 10 +-
meta/recipes-devtools/pseudo/pseudo_git.bb | 4 +-
.../python/python3-urllib3/CVE-2026-21441.patch | 105 +++++
.../python/python3-urllib3_2.2.2.bb | 1 +
.../python/python3/CVE-2025-13837.patch | 162 +++++++
meta/recipes-devtools/python/python3_3.12.12.bb | 1 +
.../lighttpd/lighttpd/0001-mod_dirlisting.patch | 48 +++
meta/recipes-extended/lighttpd/lighttpd_1.4.74.bb | 1 +
.../ffmpeg/ffmpeg/CVE-2024-35365.patch | 62 ---
.../ffmpeg/ffmpeg/CVE-2024-36618.patch | 36 --
.../ffmpeg/ffmpeg/CVE-2025-1594.patch | 105 -----
.../ffmpeg/{ffmpeg_6.1.3.bb => ffmpeg_6.1.4.bb} | 7 +-
.../libpng/files/CVE-2026-22695.patch | 77 ++++
.../libpng/files/CVE-2026-22801.patch | 173 ++++++++
meta/recipes-multimedia/libpng/libpng_1.6.42.bb | 2 +
.../libtheora/libtheora_1.1.1.bb | 2 +
.../recipes-support/curl/curl/CVE-2025-10148.patch | 57 +++
.../recipes-support/curl/curl/CVE-2025-14524.patch | 44 ++
meta/recipes-support/curl/curl_8.7.1.bb | 2 +
.../gnutls/libtasn1/CVE-2025-13151.patch | 30 ++
meta/recipes-support/gnutls/libtasn1_4.20.0.bb | 1 +
scripts/contrib/improve_kernel_cve_report.py | 467 +++++++++++++++++++++
46 files changed, 2434 insertions(+), 218 deletions(-)
create mode 100644 meta/recipes-connectivity/inetutils/inetutils/CVE-2026-24061-1.patch
create mode 100644 meta/recipes-connectivity/inetutils/inetutils/CVE-2026-24061-2.patch
create mode 100644 meta/recipes-core/expat/expat/CVE-2026-24515-01.patch
create mode 100644 meta/recipes-core/expat/expat/CVE-2026-24515-02.patch
create mode 100644 meta/recipes-core/expat/expat/CVE-2026-25210-01.patch
create mode 100644 meta/recipes-core/expat/expat/CVE-2026-25210-02.patch
create mode 100644 meta/recipes-core/expat/expat/CVE-2026-25210-03.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-0988.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-0989.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-0990.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-0992-01.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-0992-02.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-0992-03.patch
create mode 100644 meta/recipes-devtools/python/python3-urllib3/CVE-2026-21441.patch
create mode 100644 meta/recipes-devtools/python/python3/CVE-2025-13837.patch
create mode 100644 meta/recipes-extended/lighttpd/lighttpd/0001-mod_dirlisting.patch
delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-35365.patch
delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2024-36618.patch
delete mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2025-1594.patch
rename meta/recipes-multimedia/ffmpeg/{ffmpeg_6.1.3.bb => ffmpeg_6.1.4.bb} (98%)
create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-22695.patch
create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-22801.patch
create mode 100644 meta/recipes-support/curl/curl/CVE-2025-10148.patch
create mode 100644 meta/recipes-support/curl/curl/CVE-2025-14524.patch
create mode 100644 meta/recipes-support/gnutls/libtasn1/CVE-2025-13151.patch
create mode 100755 scripts/contrib/improve_kernel_cve_report.py
Best regards,
--
Paul Barker
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 252 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-04 8:23 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 8:22 [OE-core][scarthgap 00/27] Pull request (cover letter only) Yoann Congal
-- strict thread matches above, loose matches on Subject: below --
2026-02-12 13:27 Yoann Congal
2026-02-13 8:51 ` Paul Barker
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox