* [OE-core][wrynose 01/79] rootfs.py: fix run-postinsts removal on multilib images
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 02/79] wireless-regdb: upgrade 2026.05.30 -> 2026.09.03 Yoann Congal
` (77 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Kyungjik Min <dpmin7@gmail.com>
ROOTFS_BOOTSTRAP_INSTALL in image.bbclass unconditionally stages
run-postinsts into every image. When no delayed postinsts remain,
_uninstall_unneeded() is supposed to remove it again, but the removal
call used the bare "run-postinsts" package name without applying
MLPREFIX.
On a multilib image (e.g. lib32-core-image-minimal), the package that
is actually installed is lib32-run-postinsts, so the unprefixed
removal silently matches nothing and run-postinsts leaks into the
final image manifest, along with its now-pointless init script /
systemd unit.
Expand MLPREFIX before removing the package, matching the pattern
already used elsewhere in oe-core (e.g. oe/package.py) for
package-name lookups that need to work across multilib variants.
Signed-off-by: Kyungjik Min <dp.min@lge.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit dfa5673907bdc5211671ecdfce8ab1fb332eae48)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/lib/oe/rootfs.py | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/meta/lib/oe/rootfs.py b/meta/lib/oe/rootfs.py
index 7ef7e71f9e1..3504762b7ea 100644
--- a/meta/lib/oe/rootfs.py
+++ b/meta/lib/oe/rootfs.py
@@ -267,7 +267,8 @@ class Rootfs(object, metaclass=ABCMeta):
delayed_postinsts = self._get_delayed_postinsts()
if delayed_postinsts is None:
if os.path.exists(self.d.expand("${IMAGE_ROOTFS}${sysconfdir}/init.d/run-postinsts")) or os.path.exists(self.d.expand("${IMAGE_ROOTFS}${systemd_system_unitdir}/run-postinsts.service")):
- self.pm.remove(["run-postinsts"])
+ mlprefix = self.d.getVar('MLPREFIX') or ""
+ self.pm.remove([mlprefix + "run-postinsts"])
image_rorfs = bb.utils.contains("IMAGE_FEATURES", "read-only-rootfs",
True, False, self.d) and \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 02/79] wireless-regdb: upgrade 2026.05.30 -> 2026.09.03
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 01/79] rootfs.py: fix run-postinsts removal on multilib images Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 03/79] ca-certificates: upgrade 20260601 -> 20260816 Yoann Congal
` (76 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 7e92e1fe36a5767a7b31d96b9897357e0aa28cec)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...ireless-regdb_2026.05.30.bb => wireless-regdb_2026.09.03.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-kernel/wireless-regdb/{wireless-regdb_2026.05.30.bb => wireless-regdb_2026.09.03.bb} (94%)
diff --git a/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb b/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.09.03.bb
similarity index 94%
rename from meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb
rename to meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.09.03.bb
index e544b729656..ad84208f6e9 100644
--- a/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb
+++ b/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.09.03.bb
@@ -5,7 +5,7 @@ LICENSE = "ISC"
LIC_FILES_CHKSUM = "file://LICENSE;md5=07c4f6dea3845b02a18dc00c8c87699c"
SRC_URI = "https://www.kernel.org/pub/software/network/${BPN}/${BP}.tar.xz"
-SRC_URI[sha256sum] = "8a27bfc081bafed8c24dd70fab0d96f098e5a0bfcd08d3da672595f225ab8993"
+SRC_URI[sha256sum] = "b22e0901227b820cd1c280abe681a15b773a5103a5e10dc442e94ebb34cbf58d"
inherit bin_package allarch
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 03/79] ca-certificates: upgrade 20260601 -> 20260816
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 01/79] rootfs.py: fix run-postinsts removal on multilib images Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 02/79] wireless-regdb: upgrade 2026.05.30 -> 2026.09.03 Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 04/79] cmake-native: use bundled nghttp2 with bundled curl Yoann Congal
` (75 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Source: debian/changelog
ca-certificates (20260816) unstable; urgency=medium
* Update Mozilla certificate authority bundle to version 2.90
The following certificate authorities were added (+):
+ "SECOM TLS ECC Root CA 2024"
+ "SECOM TLS RSA Root CA 2024"
+ "Telia EC TLS Root CA v3"
+ "Telia RSA TLS Root CA v3"
The following certificate authorities were removed (-):
- "Atos TrustedRoot 2011"
- "Entrust Root Certification Authority"
- "SecureSign Root CA12"
- "ePKI Root Certification Authority"
-- Julien Cristau <jcristau@debian.org> Sun, 16 Aug 2026 23:04:36 +0200
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit e639396818e7152896e75364cff5fb97ae19cb32)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...vert-mozilla-certdata2pem.py-print-a-warning-for-e.patch | 6 +++---
...date-ca-certificates-don-t-use-Debianisms-in-run-p.patch | 2 +-
...date-ca-certificates-use-relative-symlinks-from-ET.patch | 2 +-
...certificates_20260601.bb => ca-certificates_20260816.bb} | 2 +-
4 files changed, 6 insertions(+), 6 deletions(-)
rename meta/recipes-support/ca-certificates/{ca-certificates_20260601.bb => ca-certificates_20260816.bb} (97%)
diff --git a/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch b/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch
index 1226508c983..001b4686246 100644
--- a/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch
+++ b/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch
@@ -1,4 +1,4 @@
-From 743774cd53ed1c45bb660eddacf6dadb5ee3e145 Mon Sep 17 00:00:00 2001
+From 8ea56b7d5eadb04309dc3cf1e6b0d94d1d053d80 Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Mon, 18 Oct 2021 12:05:49 +0200
Subject: [PATCH] Revert "mozilla/certdata2pem.py: print a warning for expired
@@ -16,10 +16,10 @@ Signed-off-by: Alexander Kanavin <alex@linutronix.de>
3 files changed, 1 insertion(+), 13 deletions(-)
diff --git a/debian/changelog b/debian/changelog
-index dbe3e9c..496e05d 100644
+index 7ad495f..058ef5e 100644
--- a/debian/changelog
+++ b/debian/changelog
-@@ -156,7 +156,6 @@ ca-certificates (20211004) unstable; urgency=low
+@@ -234,7 +234,6 @@ ca-certificates (20211004) unstable; urgency=low
- "Trustis FPS Root CA"
- "Staat der Nederlanden Root CA - G3"
* Blacklist expired root certificate "DST Root CA X3" (closes: #995432)
diff --git a/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch b/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch
index 1a29da756fc..dcfa3554117 100644
--- a/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch
+++ b/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch
@@ -1,4 +1,4 @@
-From 63086d41f76b1c3357e23c6509df72d3f75af20c Mon Sep 17 00:00:00 2001
+From bab2e13b69af12c1864cccf371ebc4ef57a6fec2 Mon Sep 17 00:00:00 2001
From: Ross Burton <ross.burton@intel.com>
Date: Mon, 6 Jul 2015 15:19:41 +0100
Subject: [PATCH] ca-certificates: remove Debianism in run-parts invocation
diff --git a/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch b/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch
index 929945b56f9..4d97c81b0d7 100644
--- a/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch
+++ b/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch
@@ -1,4 +1,4 @@
-From a69933f96a8675369de702bdb55e57dc21f65e7f Mon Sep 17 00:00:00 2001
+From 8a5b4e2dd1479de0338db7a7234d037ef0f71c2f Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Andr=C3=A9=20Draszik?= <andre.draszik@jci.com>
Date: Wed, 28 Mar 2018 16:45:05 +0100
Subject: [PATCH] update-ca-certificates: use relative symlinks from
diff --git a/meta/recipes-support/ca-certificates/ca-certificates_20260601.bb b/meta/recipes-support/ca-certificates/ca-certificates_20260816.bb
similarity index 97%
rename from meta/recipes-support/ca-certificates/ca-certificates_20260601.bb
rename to meta/recipes-support/ca-certificates/ca-certificates_20260816.bb
index 1bc64fe34a4..9dd3a05948c 100644
--- a/meta/recipes-support/ca-certificates/ca-certificates_20260601.bb
+++ b/meta/recipes-support/ca-certificates/ca-certificates_20260816.bb
@@ -14,7 +14,7 @@ DEPENDS:class-nativesdk = "openssl-native"
# Need rehash from openssl and run-parts from debianutils
PACKAGE_WRITE_DEPS += "openssl-native debianutils-native"
-SRC_URI[sha256sum] = "7ab6301f7f34eef90a4d278647c260bc0762e0e14561f4649854cf4b0d4bea21"
+SRC_URI[sha256sum] = "d939bcdd0cb058712cf4175bac76997676eb8b68fe9473765e1b40fb3d5b186a"
SRC_URI = "${DEBIAN_MIRROR}/main/c/ca-certificates/${BPN}_${PV}.tar.xz \
file://0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch \
file://0003-update-ca-certificates-use-relative-symlinks-from-ET.patch \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 04/79] cmake-native: use bundled nghttp2 with bundled curl
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (2 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 03/79] ca-certificates: upgrade 20260601 -> 20260816 Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 05/79] vim: Fix CVE-2026-52858 regression Yoann Congal
` (74 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Himanshu Jadon <hjadon@cisco.com>
cmake.inc enables system library lookup through
CMAKE_USE_SYSTEM_LIBRARIES=1. cmake-native already keeps curl bundled,
but it did not also disable system nghttp2 lookup. With CMake 4.3.1,
the bundled cmcurl configure can enable nghttp2 when headers are found
on the host. The later compile uses only the OE native sysroot, so the
build can fail with:
fatal error: nghttp2/nghttp2.h: No such file or directory
Disable system nghttp2 lookup for cmake-native also. This keeps it
consistent with the existing bundled curl setting instead of adding a
new native dependency because the host happened to expose nghttp2
during configure.
Add the bundled cmnghttp2 license checksum because the native build now
uses that copy explicitly.
Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 0b20ba549d6f17af40b9877eb9ab0c52ca62a18c)
Backport note:
CMake 4.3.1 used by Wrynose has the same behavior: with
CMAKE_USE_SYSTEM_LIBRARIES=1 and system curl disabled,
CMAKE_USE_SYSTEM_NGHTTP2 defaults to ON. If the host provides nghttp2,
configure records the host include and library paths, while do_compile
uses only the OE native sysroot. Therefore this setting is needed for
Wrynose as well.
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/cmake/cmake-native_4.3.1.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/cmake/cmake-native_4.3.1.bb b/meta/recipes-devtools/cmake/cmake-native_4.3.1.bb
index a859cef1517..911155773cc 100644
--- a/meta/recipes-devtools/cmake/cmake-native_4.3.1.bb
+++ b/meta/recipes-devtools/cmake/cmake-native_4.3.1.bb
@@ -15,6 +15,7 @@ LIC_FILES_CHKSUM:append = " \
file://Utilities/cmlibrhash/COPYING;md5=a8c2a557a5c53b1c12cddbee98c099af \
file://Utilities/cmlibuv/LICENSE;md5=ad93ca1fffe931537fcf64f6fcce084d \
file://Utilities/cmcurl/COPYING;md5=72f4e9890e99e68d77b7e40703d789b8 \
+ file://Utilities/cmnghttp2/COPYING;md5=764abdf30b2eadd37ce47dcbce0ea1ec \
file://Utilities/cmcppdap/LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57 \
"
@@ -34,6 +35,7 @@ EXTRA_OECMAKE += "\
-DCMAKE_DISABLE_FIND_PACKAGE_Libidn2=ON \
-DENABLE_ACL=0 -DHAVE_ACL_LIBACL_H=0 \
-DHAVE_SYS_ACL_H=0 \
+ -DCMAKE_USE_SYSTEM_LIBRARY_NGHTTP2=0 \
"
# Ensure e2fsprogs isn't found on the host to remove a build dependency and reproducible builds.
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 05/79] vim: Fix CVE-2026-52858 regression
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (3 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 04/79] cmake-native: use bundled nghttp2 with bundled curl Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 06/79] kernel-yocto-rust: Add clang toolchain check for riscv64 Yoann Congal
` (73 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
This patch fixes a regression introduced by the CVE-2026-52858 fix
already carried by OE-Core in commit [1]. The original security fix
added the g:pythoncomplete_allow_import opt-in, but the documented
behavior was broken because vim was not imported in the completion
class scope. This patch applies upstream Vim patch 9.2.0568 to restore
that behavior.
[1] https://github.com/openembedded/openembedded-core/commit/24ef5a9dfffe7b3d96fb62c0d3248348696c9115
[2] https://github.com/vim/vim/commit/4b850457e12e1a678dd209f2868154f7553cbf8d
[3] https://github.com/vim/vim/commit/868ad62cb8bf8038322eab2badd31bd98b02b9df
[4] https://github.com/vim/vim/security/advisories/GHSA-52mc-rq6p-rc7c
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-52858-regression.patch | 93 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 94 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-52858-regression.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-52858-regression.patch b/meta/recipes-support/vim/files/CVE-2026-52858-regression.patch
new file mode 100644
index 00000000000..50392fb76f1
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-52858-regression.patch
@@ -0,0 +1,93 @@
+From 8075209bb1e721ca89c2e7fd5d216d7fe2bd3ea6 Mon Sep 17 00:00:00 2001
+From: thinca <thinca@gmail.com>
+Date: Sun, 31 May 2026 12:33:07 +0000
+Subject: [PATCH] patch 9.2.0568: pythoncomplete: g:pythoncomplete_allow_import
+ had no effect
+
+Problem: The security patch 9.2.0561 added a vim.eval() call inside
+ Completer.evalsource() to honor g:pythoncomplete_allow_import.
+ But the 'vim' module is only imported inside the outer
+ vimcomplete() / vimpy3complete() function, not at the script's
+ top level, so referring to it from a Completer method raises
+ NameError. The surrounding bare 'except' silently swallows
+ the error and leaves allow_imports at 0, meaning the opt-in
+ never takes effect -- 'import os' (and any other
+ buffer-level import) is always skipped, no candidates are
+ produced for 'os.<...>' and
+ Test_popup_and_preview_autocommand() fails on the Windows
+ CI matrix (Linux skips the test because Python 2 is absent).
+Solution: Re-import 'vim' at the top of evalsource() in both
+ pythoncomplete.vim and python3complete.vim so the eval reads
+ the global, and set g:pythoncomplete_allow_import = 1 in the
+ test (it is the opt-in intended for callers that trust the
+ buffer contents) (thinca).
+
+closes: #20386
+
+CVE: CVE-2026-52858
+Upstream-Status: Backport [https://github.com/vim/vim/commit/868ad62cb8bf8038322eab2badd31bd98b02b9df]
+
+Backport Changes:
+- Omitted src/version.c because the Wrynose recipe remains at Vim 9.2.0340;
+ the upstream version-table hunk is not needed for this backport.
+
+Signed-off-by: thinca <thinca@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+(cherry picked from commit 868ad62cb8bf8038322eab2badd31bd98b02b9df)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ runtime/autoload/python3complete.vim | 3 +++
+ runtime/autoload/pythoncomplete.vim | 3 +++
+ src/testdir/test_popup.vim | 4 ++++
+ 3 files changed, 10 insertions(+)
+
+diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim
+index a0314242b..bdabf62c8 100644
+--- a/runtime/autoload/python3complete.vim
++++ b/runtime/autoload/python3complete.vim
+@@ -158,6 +158,9 @@ class Completer(object):
+ self.parser = PyParser()
+
+ def evalsource(self,text,line=0):
++ # vim is imported locally in vimpy3complete(); re-import here so the
++ # vim.eval() below works (otherwise NameError, silently caught).
++ import vim
+ sc = self.parser.parse(text,line)
+ try: allow_imports = int(
+ vim.eval("get(g:, 'pythoncomplete_allow_import', 0)"))
+diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim
+index 39b1efd29..761488244 100644
+--- a/runtime/autoload/pythoncomplete.vim
++++ b/runtime/autoload/pythoncomplete.vim
+@@ -172,6 +172,9 @@ class Completer(object):
+ self.parser = PyParser()
+
+ def evalsource(self,text,line=0):
++ # vim is imported locally in vimcomplete(); re-import here so the
++ # vim.eval() below works (otherwise NameError, silently caught).
++ import vim
+ sc = self.parser.parse(text,line)
+ try: allow_imports = int(
+ vim.eval("get(g:, 'pythoncomplete_allow_import', 0)"))
+diff --git a/src/testdir/test_popup.vim b/src/testdir/test_popup.vim
+index fac2a7592..55c2f232d 100644
+--- a/src/testdir/test_popup.vim
++++ b/src/testdir/test_popup.vim
+@@ -723,6 +723,9 @@ func Test_popup_and_preview_autocommand()
+ au!
+ au BufAdd * nested tab sball
+ augroup END
++ " Let pythoncomplete follow the buffer's 'import os' (off by default
++ " since v9.2.0561) so 'os.' can be completed.
++ let g:pythoncomplete_allow_import = 1
+ set omnifunc=pythoncomplete#Complete
+ call setline(1, 'import os')
+ " make the line long
+@@ -745,6 +748,7 @@ func Test_popup_and_preview_autocommand()
+ augroup END
+ augroup! MyBufAdd
+ bw!
++ unlet g:pythoncomplete_allow_import
+ endfunc
+
+ func s:run_popup_and_previewwindow_dump(lines, dumpfile)
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 77f681410a9..b3732cb780e 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -21,6 +21,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-45130.patch \
file://CVE-2026-46483.patch \
file://CVE-2026-52858.patch \
+ file://CVE-2026-52858-regression.patch \
file://CVE-2026-52859.patch \
file://CVE-2026-52860.patch \
file://CVE-2026-42307.patch \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 06/79] kernel-yocto-rust: Add clang toolchain check for riscv64
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (4 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 05/79] vim: Fix CVE-2026-52858 regression Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 07/79] python3-cryptography: Fix CVE-2026-69248 Yoann Congal
` (72 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Harish Sadineni <Harish.Sadineni@windriver.com>
Kernel Rust support on riscv64 requires Clang. Wrynose doesn't
provide a Clang toolchain for kernel builds, but downstream layers
may add this support via a linux-yocto_%.bbappend. Rather than
unconditionally skipping riscv64, check whether a Clang toolchain
is available and only error out with a clear message when it isn't,
so that users with Clang-enabled downstream configurations aren't broken.
Signed-off-by: Harish Sadineni <Harish.Sadineni@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: fixed a typo in message. This matches master commit 2b228490b7ef]
---
meta/classes-recipe/kernel-yocto-rust.bbclass | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/meta/classes-recipe/kernel-yocto-rust.bbclass b/meta/classes-recipe/kernel-yocto-rust.bbclass
index 49f2bfc1ae8..4c0b7231e6a 100644
--- a/meta/classes-recipe/kernel-yocto-rust.bbclass
+++ b/meta/classes-recipe/kernel-yocto-rust.bbclass
@@ -25,3 +25,13 @@ do_kernel_configme:append () {
# More details in: https://lists.openembedded.org/g/openembedded-core/message/229336
# Disable ccache for kernel build if kernel rust support is enabled to workaround this.
CCACHE_DISABLE ?= "1"
+
+python () {
+ if d.getVar('TARGET_ARCH') == 'riscv64' and d.getVar('TOOLCHAIN') != 'clang':
+ raise bb.parse.SkipRecipe(
+ "Rust support in the kernel on riscv64 requires kernel to be build with clang "
+ "toolchain, but the kernel is built with toolchain '%s'. See "
+ "https://docs.kernel.org/rust/arch-support.html for details."
+ % d.getVar('TOOLCHAIN')
+ )
+}
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 07/79] python3-cryptography: Fix CVE-2026-69248
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (5 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 06/79] kernel-yocto-rust: Add clang toolchain check for riscv64 Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 08/79] python3-cryptography: Fix CVE-2026-69249 Yoann Congal
` (71 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/cve-2026-69248
[2] https://security-tracker.debian.org/tracker/CVE-2026-69248
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../python/python3-cryptography.bb | 1 +
.../python3-cryptography/CVE-2026-69248.patch | 302 ++++++++++++++++++
2 files changed, 303 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch
diff --git a/meta/recipes-devtools/python/python3-cryptography.bb b/meta/recipes-devtools/python/python3-cryptography.bb
index c6561deb3c4..5c1de9192b1 100644
--- a/meta/recipes-devtools/python/python3-cryptography.bb
+++ b/meta/recipes-devtools/python/python3-cryptography.bb
@@ -15,6 +15,7 @@ SRC_URI[sha256sum] = "e4cfd68c5f3e0bfdad0d38e023239b96a2fe84146481852dffbcca442c
SRC_URI += "file://0001-pyproject.toml-remove-benchmark-disable-option.patch \
file://0002-Fix-installing-stray-files-into-site-packages.patch \
+ file://CVE-2026-69248.patch \
file://check-memfree.py \
file://run-ptest \
"
diff --git a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch
new file mode 100644
index 00000000000..66cfa12a6c1
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch
@@ -0,0 +1,302 @@
+From 4d035a4225965edeffd312079a510ef25fcfdcb2 Mon Sep 17 00:00:00 2001
+From: William Woodruff <william@yossarian.net>
+Date: Thu, 21 May 2026 20:44:05 -0400
+Subject: [PATCH] x509: distinguish NC kinds when evaluating wildcard DNS SANs
+ (#14888)
+
+* x509: distinguish NC kinds when evaluating wildcard DNS SANs
+
+* Bump x509-limbo
+
+Upstream-Status: Backport [https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2]
+CVE: CVE-2026-69248
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ .../cryptography-x509-verification/src/lib.rs | 43 ++++-
+ .../src/types.rs | 165 ++++++++++++------
+ 2 files changed, 145 insertions(+), 63 deletions(-)
+
+diff --git a/src/rust/cryptography-x509-verification/src/lib.rs b/src/rust/cryptography-x509-verification/src/lib.rs
+index c59f84f..60c89d4 100644
+--- a/src/rust/cryptography-x509-verification/src/lib.rs
++++ b/src/rust/cryptography-x509-verification/src/lib.rs
+@@ -147,6 +147,7 @@ impl<'a, 'chain> NameChain<'a, 'chain> {
+
+ fn evaluate_single_constraint<B: CryptoOps>(
+ &self,
++ kind: SubtreeKind,
+ constraint: &GeneralName<'chain>,
+ san: &GeneralName<'chain>,
+ budget: &mut Budget,
+@@ -155,14 +156,18 @@ impl<'a, 'chain> NameChain<'a, 'chain> {
+
+ match (constraint, san) {
+ (GeneralName::DNSName(constraint), GeneralName::DNSName(name)) => {
+- // NOTE: A DNS SAN can be a wildcard pattern instead of a normal DNS name.
+- // These are handled by matching unconditionally on the inner name,
+- // since a NC of `foo.com` will match both `foo.com` and any arbitrarily deep
+- // subdomain of `foo.com`, where a wildcard SAN like `*.foo.com` will only
+- // match exactly one subdomain of `foo.com`. Therefore, the NC's matching
+- // set is a strict superset of any possible wildcard SAN pattern.
++ // NOTE: A DNS SAN can be a wildcard pattern (e.g. `*.foo.com`)
++ // rather than an ordinary DNS name. A wildcard represents a
++ // *set* of names, so the check depends on which subtree we're
++ // evaluating: a `permittedSubtrees` constraint must contain
++ // *every* name the wildcard can expand to, whereas an
++ // `excludedSubtrees` constraint matches if it overlaps the
++ // wildcard at all. We dispatch on `kind` accordingly.
+ match (DNSConstraint::new(constraint.0), DNSPattern::new(name.0)) {
+- (Some(constraint), Some(name)) => Ok(Applied(constraint.matches(&name))),
++ (Some(constraint), Some(name)) => Ok(Applied(match kind {
++ SubtreeKind::Permitted => constraint.permits(&name),
++ SubtreeKind::Excluded => constraint.excludes(&name),
++ })),
+ (_, None) => Err(ValidationError::new(ValidationErrorKind::Other(format!(
+ "unsatisfiable DNS name constraint: malformed SAN {}",
+ name.0
+@@ -232,7 +237,12 @@ impl<'a, 'chain> NameChain<'a, 'chain> {
+ let mut permit = true;
+ if let Some(permitted_subtrees) = &constraints.permitted_subtrees {
+ for p in permitted_subtrees.clone() {
+- let status = self.evaluate_single_constraint(&p.base, &san, budget)?;
++ let status = self.evaluate_single_constraint(
++ SubtreeKind::Permitted,
++ &p.base,
++ &san,
++ budget,
++ )?;
+ if status.is_applied() {
+ permit = status.is_match();
+ if permit {
+@@ -250,7 +260,12 @@ impl<'a, 'chain> NameChain<'a, 'chain> {
+
+ if let Some(excluded_subtrees) = &constraints.excluded_subtrees {
+ for e in excluded_subtrees.clone() {
+- let status = self.evaluate_single_constraint(&e.base, &san, budget)?;
++ let status = self.evaluate_single_constraint(
++ SubtreeKind::Excluded,
++ &e.base,
++ &san,
++ budget,
++ )?;
+ if status.is_match() {
+ return Err(ValidationError::new(ValidationErrorKind::Other(
+ "excluded name constraint matched SAN".into(),
+@@ -284,6 +299,16 @@ struct ChainBuilder<'a, 'chain, B: CryptoOps> {
+ store: &'a Store<'chain, B>,
+ }
+
++/// Identifies which kind of name constraint subtree a SAN is being evaluated
++/// against. The two subtree kinds use different matching semantics for
++/// wildcard DNS SANs (containment vs. overlap); see [`DNSConstraint::permits`]
++/// and [`DNSConstraint::excludes`].
++#[derive(Clone, Copy)]
++enum SubtreeKind {
++ Permitted,
++ Excluded,
++}
++
+ // When applying a name constraint, we need to distinguish between a few different scenarios:
+ // * `Applied(true)`: The name constraint is the same type as the SAN and matches.
+ // * `Applied(false)`: The name constraint is the same type as the SAN and does not match.
+diff --git a/src/rust/cryptography-x509-verification/src/types.rs b/src/rust/cryptography-x509-verification/src/types.rs
+index 86316f4..0ec0be2 100644
+--- a/src/rust/cryptography-x509-verification/src/types.rs
++++ b/src/rust/cryptography-x509-verification/src/types.rs
+@@ -150,44 +150,69 @@ impl<'a> DNSConstraint<'a> {
+ DNSName::new(pattern).map(Self)
+ }
+
+- /// Returns true if this `DNSConstraint` matches the given `DNSPattern`.
++ /// Returns true if the given exact `DNSName` falls within this
++ /// constraint's subtree.
+ ///
+- /// Constraint matching is defined by RFC 5280: any DNS name that can
+- /// be constructed by simply adding zero or more labels to the left-hand
+- /// side of the name satisfies the name constraint.
++ /// Per RFC 5280, a name satisfies the constraint if it can be constructed
++ /// by adding zero or more labels to the left-hand side of the constraint's
++ /// name (i.e. it is the constraint's name, or a subdomain of it).
++ fn contains(&self, name: &DNSName<'_>) -> bool {
++ // NOTE: This may seem like an obtuse way to perform label matching,
++ // but it saves us a few allocations: doing a substring check instead
++ // would require us to clone each string and do case normalization.
++ // Note also that we check the length in advance: Rust's zip
++ // implementation terminates with the shorter iterator, so we need
++ // to first check that the candidate name is at least as long as
++ // the constraint it's matching against.
++ name.as_str().len() >= self.0.as_str().len()
++ && self
++ .0
++ .rlabels()
++ .zip(name.rlabels())
++ .all(|(a, o)| a.eq_ignore_ascii_case(o))
++ }
++
++ /// Returns true if the given `DNSPattern` is permitted by this constraint,
++ /// for use with a `permittedSubtrees` name constraint.
+ ///
+- /// On top of what RFC 5280 specifies, we define behavior for wildcard
+- /// patterns (which are not covered by RFC 5280): a wildcard pattern
+- /// matches a constraint if the pattern matches the constraint's inner name,
+- /// _or_ if the pattern's inner name matches the constraint.
+- /// This allows us to reject DNS names like `*.example.com` when
+- /// the constraint is `example.com` or `bar.example.com`.
+- pub fn matches(&self, name: &DNSPattern<'_>) -> bool {
+- match name {
+- DNSPattern::Exact(name) => {
+- // NOTE: This may seem like an obtuse way to perform label matching,
+- // but it saves us a few allocations: doing a substring check instead
+- // would require us to clone each string and do case normalization.
+- // Note also that we check the length in advance: Rust's zip
+- // implementation terminates with the shorter iterator, so we need
+- // to first check that the candidate name is at least as long as
+- // the constraint it's matching against.
+- name.as_str().len() >= self.0.as_str().len()
+- && self
+- .0
+- .rlabels()
+- .zip(name.rlabels())
+- .all(|(a, o)| a.eq_ignore_ascii_case(o))
+- }
+- DNSPattern::Wildcard(inner) => {
+- // NOTE: This check is not as simple as a single pattern match,
+- // since we need two subtly distinct cases here:
+- // 1. Constraint `bar.example.com` on `*.example.com`
+- // 2. Constraint `example.com` on `*.example.com`
+- // The first cases is handled by `DNSPattern::matches`, and the second is handled
+- // by `DNSConstraint::matches`.
+- name.matches(&self.0) || self.matches(&DNSPattern::Exact(inner.clone()))
+- }
++ /// A pattern is permitted only if *every* name it can represent falls
++ /// within the constraint's subtree. An exact name is permitted by ordinary
++ /// subtree containment (per RFC 5280).
++ ///
++ /// Wildcard patterns are not covered by RFC 5280; we define their behavior
++ /// here. A wildcard pattern `*.X` is permitted only if its base name `X`
++ /// itself falls within the constraint's subtree. This is stricter than
++ /// mere overlap: `*.example.com` is *not* permitted by `foo.example.com`,
++ /// since it can also expand to a sibling such as `bar.example.com` that
++ /// lies outside the permitted subtree.
++ pub fn permits(&self, pattern: &DNSPattern<'_>) -> bool {
++ match pattern {
++ DNSPattern::Exact(name) => self.contains(name),
++ DNSPattern::Wildcard(base) => self.contains(base),
++ }
++ }
++
++ /// Returns true if the given `DNSPattern` is excluded by this constraint,
++ /// for use with an `excludedSubtrees` name constraint.
++ ///
++ /// A pattern is excluded if *any* name it can represent falls within the
++ /// constraint's subtree. An exact name is excluded by ordinary subtree
++ /// containment (per RFC 5280).
++ ///
++ /// Wildcard patterns are not covered by RFC 5280; we define their behavior
++ /// here. A wildcard pattern `*.X` is excluded if it overlaps the subtree
++ /// at all, which happens in two subtly distinct cases:
++ ///
++ /// 1. The constraint is more specific than the wildcard, e.g. constraint
++ /// `bar.example.com` and pattern `*.example.com` (which can expand to
++ /// `bar.example.com`). This is handled by `DNSPattern::matches`.
++ /// 2. The wildcard's base name falls within the subtree, e.g. constraint
++ /// `example.com` and pattern `*.example.com`. This is handled by
++ /// `DNSConstraint::contains`.
++ pub fn excludes(&self, pattern: &DNSPattern<'_>) -> bool {
++ match pattern {
++ DNSPattern::Exact(name) => self.contains(name),
++ DNSPattern::Wildcard(base) => pattern.matches(&self.0) || self.contains(base),
+ }
+ }
+ }
+@@ -590,37 +615,69 @@ mod tests {
+ }
+
+ #[test]
+- fn test_dnsconstraint_matches() {
++ fn test_dnsconstraint_exact() {
+ let example_com = DNSConstraint::new("example.com").unwrap();
+
+- // Exact domain and arbitrary subdomains match.
+- assert!(example_com.matches(&DNSPattern::new("example.com").unwrap()));
+- assert!(example_com.matches(&DNSPattern::new("foo.example.com").unwrap()));
+- assert!(example_com.matches(&DNSPattern::new("foo.bar.baz.quux.example.com").unwrap()));
++ // For exact patterns, `permits` and `excludes` behave identically:
++ // the pattern must fall within the constraint's subtree.
++ for permitted in [
++ "example.com",
++ "foo.example.com",
++ "foo.bar.baz.quux.example.com",
++ ] {
++ let pattern = DNSPattern::new(permitted).unwrap();
++ assert!(example_com.permits(&pattern));
++ assert!(example_com.excludes(&pattern));
++ }
+
+ // Parent domains, distinct domains, and substring domains do not match.
+- assert!(!example_com.matches(&DNSPattern::new("com").unwrap()));
+- assert!(!example_com.matches(&DNSPattern::new("badexample.com").unwrap()));
+- assert!(!example_com.matches(&DNSPattern::new("wrong.com").unwrap()));
++ for rejected in ["com", "badexample.com", "wrong.com"] {
++ let pattern = DNSPattern::new(rejected).unwrap();
++ assert!(!example_com.permits(&pattern));
++ assert!(!example_com.excludes(&pattern));
++ }
+ }
+
+ #[test]
+- fn test_dnsconstraint_matches_wildcard() {
++ fn test_dnsconstraint_permits_wildcard() {
++ let com = DNSConstraint::new("com").unwrap();
++ let example_com = DNSConstraint::new("example.com").unwrap();
++ let foo_example_com = DNSConstraint::new("foo.example.com").unwrap();
++ let any_example_com = DNSPattern::new("*.example.com").unwrap();
++
++ // A wildcard `*.example.com` is permitted only by constraints whose
++ // subtree contains *every* name the wildcard can expand to, i.e. those
++ // that contain `example.com` itself.
++ assert!(com.permits(&any_example_com));
++ assert!(example_com.permits(&any_example_com));
++
++ // A constraint more specific than the wildcard's base does *not*
++ // permit it: the wildcard can expand to siblings outside the subtree
++ // (e.g. `*.example.com` can be `bar.example.com`, which lies outside
++ // `foo.example.com`).
++ assert!(!foo_example_com.permits(&any_example_com));
++ }
++
++ #[test]
++ fn test_dnsconstraint_excludes_wildcard() {
+ let com = DNSConstraint::new("com").unwrap();
+ let example_com = DNSConstraint::new("example.com").unwrap();
+ let bar_example_com = DNSConstraint::new("bar.example.com").unwrap();
+ let baz_bar_example_com = DNSConstraint::new("baz.bar.example.com").unwrap();
+ let any_example_com = DNSPattern::new("*.example.com").unwrap();
+
+- assert!(com.matches(&any_example_com));
+- assert!(example_com.matches(&any_example_com));
+- assert!(bar_example_com.matches(&any_example_com));
+-
+- // A constraint on `baz.bar.example.com` doesn't match `*.example.com`,
+- // since `baz.bar.example.com` matches zero or more sublabels of
+- // `baz.bar.example.com` while `*.example.com` matches exactly one
+- // sublabel of `example.com`.
+- assert!(!baz_bar_example_com.matches(&any_example_com));
++ // A wildcard `*.example.com` is excluded by any constraint whose
++ // subtree it overlaps, including constraints more specific than the
++ // wildcard's base.
++ assert!(com.excludes(&any_example_com));
++ assert!(example_com.excludes(&any_example_com));
++ assert!(bar_example_com.excludes(&any_example_com));
++
++ // A constraint on `baz.bar.example.com` doesn't overlap
++ // `*.example.com`, since `baz.bar.example.com` matches zero or more
++ // sublabels of `baz.bar.example.com` while `*.example.com` matches
++ // exactly one sublabel of `example.com`.
++ assert!(!baz_bar_example_com.excludes(&any_example_com));
+ }
+
+ #[test]
+--
+2.43.0
+
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 08/79] python3-cryptography: Fix CVE-2026-69249
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (6 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 07/79] python3-cryptography: Fix CVE-2026-69248 Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 09/79] libxml2: upgrade 2.15.3 -> 2.15.4 Yoann Congal
` (70 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/cve-2026-69249
[2] https://security-tracker.debian.org/tracker/CVE-2026-69249
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../python/python3-cryptography.bb | 1 +
.../python3-cryptography/CVE-2026-69249.patch | 338 ++++++++++++++++++
2 files changed, 339 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
diff --git a/meta/recipes-devtools/python/python3-cryptography.bb b/meta/recipes-devtools/python/python3-cryptography.bb
index 5c1de9192b1..f3cb755ed5b 100644
--- a/meta/recipes-devtools/python/python3-cryptography.bb
+++ b/meta/recipes-devtools/python/python3-cryptography.bb
@@ -16,6 +16,7 @@ SRC_URI[sha256sum] = "e4cfd68c5f3e0bfdad0d38e023239b96a2fe84146481852dffbcca442c
SRC_URI += "file://0001-pyproject.toml-remove-benchmark-disable-option.patch \
file://0002-Fix-installing-stray-files-into-site-packages.patch \
file://CVE-2026-69248.patch \
+ file://CVE-2026-69249.patch \
file://check-memfree.py \
file://run-ptest \
"
diff --git a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
new file mode 100644
index 00000000000..f700d3f1eee
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
@@ -0,0 +1,338 @@
+From 4a12cf49675a184e47f912b00b04f3a629283582 Mon Sep 17 00:00:00 2001
+From: William Woodruff <william@yossarian.net>
+Date: Sat, 6 Jun 2026 23:30:03 -0400
+Subject: [PATCH] Add a signature validation budget during path construction
+ (#14960)
+
+* Add a signature validation budget during path construction
+
+This extends our existing NC budget check to include a budget
+for signature validations. If a path construction exceeds the
+budget by performing more than the allowed number of signature
+validation steps, the entire construction fails.
+
+For now, our budget is 128 signature validations. This is
+consistent with (higher than) Go and rustls-webpki, which
+both set a limit of 100. Like Go, we attempt to make the "best"
+use of our signature budget by ordering by likelihood, using
+AKI/SKI match as the strongest signal of fitness.
+
+* Bump limbo
+
+* Temporary commit
+
+* Revert "Temporary commit"
+
+This reverts commit bcdb6808562a8b8f484f85d21cb201cfdb2bbbd7.
+
+* Fudge a coverage test into place
+
+* Coverage for the coverage god
+
+Upstream-Status: Backport [https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582]
+CVE: CVE-2026-69249
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ .../cryptography-x509-verification/src/lib.rs | 183 +++++++++++++++++-
+ .../src/policy/mod.rs | 9 +-
+ 2 files changed, 182 insertions(+), 10 deletions(-)
+
+diff --git a/src/rust/cryptography-x509-verification/src/lib.rs b/src/rust/cryptography-x509-verification/src/lib.rs
+index 60c89d4..7ee3bb0 100644
+--- a/src/rust/cryptography-x509-verification/src/lib.rs
++++ b/src/rust/cryptography-x509-verification/src/lib.rs
+@@ -18,10 +18,14 @@ use std::vec;
+ use asn1::ObjectIdentifier;
+ use cryptography_x509::common::Asn1Read;
+ use cryptography_x509::extensions::{
+- DuplicateExtensionsError, Extensions, NameConstraints, SubjectAlternativeName,
++ AuthorityKeyIdentifier, DuplicateExtensionsError, Extensions, NameConstraints,
++ SubjectAlternativeName,
+ };
+ use cryptography_x509::name::GeneralName;
+-use cryptography_x509::oid::{NAME_CONSTRAINTS_OID, SUBJECT_ALTERNATIVE_NAME_OID};
++use cryptography_x509::oid::{
++ AUTHORITY_KEY_IDENTIFIER_OID, NAME_CONSTRAINTS_OID, SUBJECT_ALTERNATIVE_NAME_OID,
++ SUBJECT_KEY_IDENTIFIER_OID,
++};
+
+ use crate::certificate::cert_is_self_issued;
+ use crate::ops::{CryptoOps, VerificationCertificate};
+@@ -98,15 +102,23 @@ impl<B: CryptoOps> Display for ValidationError<'_, B> {
+
+ struct Budget {
+ name_constraint_checks: usize,
++ signature_checks: usize,
+ }
+
+ impl Budget {
+- // Same limit as other validators
++ // The maximum number of name constraint checks performed when attempting
++ // path construction. This is the same limit as other validators.
+ const DEFAULT_NAME_CONSTRAINT_CHECK_LIMIT: usize = 1 << 20;
+
++ // The maximum number of signature verifications performed when attempting
++ // path construction. The is similar to other validators:
++ // both Go and rustls-webpki pick 100.
++ const DEFAULT_SIGNATURE_CHECK_LIMIT: usize = 1 << 7;
++
+ fn new() -> Budget {
+ Budget {
+ name_constraint_checks: Self::DEFAULT_NAME_CONSTRAINT_CHECK_LIMIT,
++ signature_checks: Self::DEFAULT_SIGNATURE_CHECK_LIMIT,
+ }
+ }
+
+@@ -119,6 +131,15 @@ impl Budget {
+ })?;
+ Ok(())
+ }
++
++ fn signature_check<'chain, B: CryptoOps>(&mut self) -> ValidationResult<'chain, (), B> {
++ self.signature_checks = self.signature_checks.checked_sub(1).ok_or_else(|| {
++ ValidationError::new(ValidationErrorKind::FatalError(
++ "Exceeded maximum signature check limit",
++ ))
++ })?;
++ Ok(())
++ }
+ }
+
+ struct NameChain<'a, 'chain> {
+@@ -341,18 +362,57 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> {
+ }
+ }
+
++ /// Identify and return potential issuers for `cert`, considering
++ /// candidates from both the trusted store and untrusted intermediate set.
++ /// Trusted candidates are returned before untrusted intermediate
++ /// candidates, and both groups are opportunisitically ordered by
++ /// "likeliness" in terms of AKI/SKI match.
+ fn potential_issuers(
+ &self,
+ cert: &'a VerificationCertificate<'chain, B>,
+- ) -> impl Iterator<Item = &'a VerificationCertificate<'chain, B>> + '_ {
+- // TODO: Optimizations:
+- // * Search by AKI and other identifiers?
+- self.store
++ cert_extensions: &Extensions<'chain>,
++ ) -> Vec<&'a VerificationCertificate<'chain, B>> {
++ let mut candidates: Vec<&'a VerificationCertificate<'chain, B>> = self
++ .store
+ .get_by_subject(&cert.certificate().tbs_cert.issuer)
+ .iter()
+ .chain(self.intermediates.iter().filter(|&candidate| {
+ candidate.certificate().subject() == cert.certificate().issuer()
+ }))
++ .collect();
++
++ let want_kid: Option<&[u8]> = cert_extensions
++ .get_extension(&AUTHORITY_KEY_IDENTIFIER_OID)
++ .and_then(|ext| ext.value::<AuthorityKeyIdentifier<'_, Asn1Read>>().ok())
++ .and_then(|aki| aki.key_identifier);
++
++ // This mirrors Go's `findPotentialParents`: we have a global
++ // signature budget, so we want to bucket candidates by likeliness
++ // to avoid wasting budget on (potentially adversarial) name collisions.
++ //
++ // Observe that we use a stable sort to preserve trusted candidates
++ // before untrusted candidates in each likeliness bucket. In other
++ // words, we always try a likely trusted candidate over an equally
++ // likely untrusted one.
++ //
++ // See: <https://github.com/golang/go/blob/d00c67f297e/src/crypto/x509/cert_pool.go#L136>
++ candidates.sort_by_key(|candidate| {
++ let have_kid: Option<&[u8]> =
++ candidate.certificate().extensions().ok().and_then(|exts| {
++ exts.get_extension(&SUBJECT_KEY_IDENTIFIER_OID)
++ .and_then(|ext| ext.value::<&[u8]>().ok())
++ });
++
++ match (want_kid, have_kid) {
++ // cert AKID matches candidate SKID, highest likelihood.
++ (Some(want), Some(have)) if want == have => 0,
++ // cert AKID and candidate SKID don't match, lowest likelihood.
++ (Some(_), Some(_)) => 2,
++ // cert AKID and/or candidate SKID is not present, medium likelihood.
++ _ => 1u8,
++ }
++ });
++ candidates
+ }
+
+ fn build_chain_inner(
+@@ -385,7 +445,8 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> {
+ // Otherwise, we collect a list of potential issuers for this cert,
+ // and continue with the first that verifies.
+ let mut last_err: Option<ValidationError<'_, B>> = None;
+- for issuing_cert_candidate in self.potential_issuers(working_cert) {
++ for issuing_cert_candidate in self.potential_issuers(working_cert, working_cert_extensions)
++ {
+ // A candidate issuer is said to verify if it both
+ // signs for the working certificate and conforms to the
+ // policy.
+@@ -395,6 +456,7 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> {
+ working_cert,
+ current_depth,
+ &issuer_extensions,
++ budget,
+ ) {
+ Ok(_) => {
+ match self.build_chain_inner(
+@@ -503,10 +565,15 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> {
+ #[cfg(test)]
+ mod tests {
+ use asn1::ParseError;
++ use cryptography_x509::certificate::Certificate;
+ use cryptography_x509::oid::SUBJECT_ALTERNATIVE_NAME_OID;
+
+ use crate::certificate::tests::PublicKeyErrorOps;
+- use crate::{ValidationError, ValidationErrorKind};
++ use crate::ops::{CryptoOps, VerificationCertificate};
++ use crate::policy::{Policy, PolicyDefinition, Subject};
++ use crate::trust_store::Store;
++ use crate::types::DNSName;
++ use crate::{Budget, ChainBuilder, NameChain, ValidationError, ValidationErrorKind};
+
+ #[test]
+ fn test_validationerror_display() {
+@@ -528,4 +595,102 @@ mod tests {
+ ValidationError::<PublicKeyErrorOps>::new(ValidationErrorKind::FatalError("oops"));
+ assert_eq!(err.to_string(), "fatal error: oops");
+ }
++
++ /// A `CryptoOps` whose public key extraction and signature verification
++ /// always succeed, so that `valid_issuer` can be driven to completion
++ /// without real cryptographic material.
++ struct NullOps;
++
++ impl CryptoOps for NullOps {
++ type Key = ();
++ type Err = ();
++ type CertificateExtra = ();
++ type PolicyExtra = ();
++
++ fn public_key(&self, _cert: &Certificate<'_>) -> Result<Self::Key, Self::Err> {
++ Ok(())
++ }
++
++ fn verify_signed_by(
++ &self,
++ _cert: &Certificate<'_>,
++ _key: &Self::Key,
++ ) -> Result<(), Self::Err> {
++ Ok(())
++ }
++
++ fn clone_public_key(_key: &Self::Key) -> Self::Key {}
++
++ fn clone_extra(_extra: &Self::CertificateExtra) -> Self::CertificateExtra {}
++ }
++
++ #[test]
++ fn test_clone() {
++ assert_eq!(NullOps::clone_public_key(&()), ());
++ assert_eq!(NullOps::clone_extra(&()), ());
++ }
++
++ // A self-issued ("looping") CA certificate that is its own issuer.
++ fn looping_ca_pem() -> pem::Pem {
++ pem::parse(
++ "-----BEGIN CERTIFICATE-----
++MIIBcjCCARmgAwIBAgIBATAKBggqhkjOPQQDAjAhMR8wHQYDVQQDDBZsb29waW5n
++IHNlbGYtc2lnbmVkIENBMB4XDTIzMTIzMTAwMDAwMFoXDTI0MDEzMTAwMDAwMFow
++ITEfMB0GA1UEAwwWbG9vcGluZyBzZWxmLXNpZ25lZCBDQTBZMBMGByqGSM49AgEG
++CCqGSM49AwEHA0IABKAoXUGnHdfXJbSXjRjeW+PCVHmlo4KEki69N5pJUA0QyQMR
++v9ySOMnWf3Ea7TR4g3zdguwTP7LdpSku3uR1QkmjQjBAMA8GA1UdEwEB/wQFMAMB
++Af8wDgYDVR0PAQH/BAQDAgGGMB0GA1UdDgQWBBR23MGdG1Ma9iR+3CxKTafD/OE0
++dTAKBggqhkjOPQQDAgNHADBEAiA4RCr07KfZdM16VfGNZAQFjvC60SWIU3RRVY/L
++qolIOwIgCaIgj9ipK0Q0p+45UJiq+L/ncrxsweJkFq/UYubzhX0=
++-----END CERTIFICATE-----",
++ )
++ .unwrap()
++ }
++
++ /// Exercises our pathlen overflow error scenario.
++ ///
++ /// This condition is logically unreachable from Python, since
++ /// we unconditionally limit signature checks to a number smaller
++ /// than `u8::MAX`, meaning that we always exhaust the signature budget
++ /// before potentially exhausting the pathlen budget.
++ ///
++ /// To test that directly, we manually lift the signature budget
++ /// and start our pathlen state right at `u8::MAX`, guaranteeing
++ /// an overflow on the immediate chain building step.
++ #[test]
++ fn test_build_chain_inner_depth_overflow() {
++ let pem = looping_ca_pem();
++ let ca = asn1::parse_single::<Certificate<'_>>(pem.contents()).unwrap();
++ let ca_exts = ca.extensions().ok().unwrap();
++
++ // The same self-issued CA is both the working certificate and its own
++ // (only) candidate issuer, so the search recurses on itself.
++ let working = VerificationCertificate::<NullOps>::new(&ca, ());
++ let intermediates = [VerificationCertificate::<NullOps>::new(&ca, ())];
++ let store: Store<'_, NullOps> = Store::new([]);
++
++ let subject = Subject::DNS(DNSName::new("example.com").unwrap());
++ let time = asn1::DateTime::new(2024, 1, 1, 0, 0, 0).unwrap();
++ let policy_def =
++ PolicyDefinition::server(NullOps, subject, time, Some(u8::MAX), None, None).unwrap();
++ let policy = Policy::new(&policy_def, ());
++
++ let builder = ChainBuilder::new(&intermediates, &policy, &store);
++ let mut budget = Budget {
++ name_constraint_checks: usize::MAX,
++ signature_checks: usize::MAX,
++ };
++
++ let name_chain = NameChain::new::<NullOps>(None, &ca_exts, false)
++ .ok()
++ .unwrap();
++ let err = builder
++ .build_chain_inner(&working, u8::MAX, &ca_exts, name_chain, &mut budget)
++ .unwrap_err();
++
++ assert!(matches!(
++ err.kind,
++ ValidationErrorKind::Other(msg) if msg.contains("current depth calculation overflowed")
++ ));
++ }
+ }
+diff --git a/src/rust/cryptography-x509-verification/src/policy/mod.rs b/src/rust/cryptography-x509-verification/src/policy/mod.rs
+index 1d82e4b..b3a1f08 100644
+--- a/src/rust/cryptography-x509-verification/src/policy/mod.rs
++++ b/src/rust/cryptography-x509-verification/src/policy/mod.rs
+@@ -30,7 +30,9 @@ pub use crate::policy::extension::{
+ PresentExtensionValidatorCallback,
+ };
+ use crate::types::{DNSName, DNSPattern, IPAddress};
+-use crate::{ValidationError, ValidationErrorKind, ValidationResult, VerificationCertificate};
++use crate::{
++ Budget, ValidationError, ValidationErrorKind, ValidationResult, VerificationCertificate,
++};
+
+ // RSA key constraints, as defined in CA/B 6.1.5.
+ const WEBPKI_MINIMUM_RSA_MODULUS: usize = 2048;
+@@ -503,6 +505,7 @@ impl<'a, B: CryptoOps> Policy<'a, B> {
+ child: &VerificationCertificate<'chain, B>,
+ current_depth: u8,
+ issuer_extensions: &Extensions<'_>,
++ budget: &mut Budget,
+ ) -> ValidationResult<'chain, (), B> {
+ // The issuer needs to be a valid CA at the current depth.
+ self.permits_ca(issuer, current_depth, issuer_extensions)
+@@ -563,6 +566,10 @@ impl<'a, B: CryptoOps> Policy<'a, B> {
+ }
+ }
+
++ // Charge the (potentially expensive) signature verification against the
++ // budget before performing it, bounding the total work an attacker can
++ // force during chain building.
++ budget.signature_check()?;
+ if self.ops.verify_signed_by(child.certificate(), pk).is_err() {
+ return Err(ValidationError::new(ValidationErrorKind::Other(
+ "signature does not match".to_string(),
+--
+2.43.0
+
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 09/79] libxml2: upgrade 2.15.3 -> 2.15.4
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (7 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 08/79] python3-cryptography: Fix CVE-2026-69249 Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 10/79] kbd: Fix CVE-2026-72693 Yoann Congal
` (69 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
v2.15.4: Sep 01 2026
- xmlregexp: Prevent out-of-bounds read in NXT macro
- fix: add missing overflow checks in dict.c, uri.c, and valid.c
- xmlregexp: Calc string length after null checking
- xpointer: Check overflow in xmlXPtrEvalXPtrPart
- xmlIO: Check for int overflow before calling writecallback
- fix(xinclude): propagate parseFlags in xmlXIncludeProcess and xmlXIncludeProcessTree
- Improve bound checks for xmlcatalog and xmllint arguments (out-of-bound)
- Fix memory leak in static Windows library (memory-leak)
- xmlreader: Copy DTD in xmlTextReaderDumpCopy
- parser: Fix double free in xmlIOParseDTD (double-free)
- parser: fix division-by-zero when maxAmpl is set to 0
- parser: Fix memory leak in xmlCtxtSetSaxHandler (memory-leak)
- catalog: Make sure to reset catalog resolve cache
- xmlAddChild: unlink node before free for text nodes (memory-leak)
- Normalize entity values in attr in xmlNodeGetContent
- Handle whitespace for date/time/duration types
- catalog: Fix NULL deref for nextCatalog without 'catalog' attribute (null-deref)
For detailed information, see the link below:
[1] https://gitlab.gnome.org/GNOME/libxml2/-/commit/96498992efa48d52b0e8b83058bd88dbdaf153c1
Note: Removed CVE-2026-11979 as it is already fixed.
CVE's Fixed:
CVE-2026-11979 (CVSSv3: 7.8): https://nvd.nist.gov/vuln/detail/CVE-2026-11979
CVE-2026-86137 (CVSSv3: 2.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86137
CVE-2026-86138 (CVSSv3: 6.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86138
CVE-2026-86139 (CVSSv3: 6.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86139
CVE-2026-86140 (CVSSv3: 8.0): https://nvd.nist.gov/vuln/detail/CVE-2026-86140
CVE-2026-86141 (CVSSv3: 2.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86141
CVE-2026-86142 (CVSSv3: 6.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86142
CVE-2026-86143 (CVSSv3: 6.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86143
CVE-2026-86144 (CVSSv3: 5.6): https://nvd.nist.gov/vuln/detail/CVE-2026-86144
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 8875c7e8dbecc0700aa6db49b66b8d77a21938b1)
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: I merged commit message from master/RP and Siddharth]
---
.../libxml/libxml2/CVE-2026-11979.patch | 81 -------------------
.../{libxml2_2.15.3.bb => libxml2_2.15.4.bb} | 3 +-
2 files changed, 1 insertion(+), 83 deletions(-)
delete mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
rename meta/recipes-core/libxml/{libxml2_2.15.3.bb => libxml2_2.15.4.bb} (96%)
diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
deleted file mode 100644
index a14e566681e..00000000000
--- a/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
+++ /dev/null
@@ -1,81 +0,0 @@
-From dfad0660f7dab3b5f8317b703b16ad0b0d12697d Mon Sep 17 00:00:00 2001
-From: Daniel Garcia Moreno <daniel.garcia@suse.com>
-Date: Fri, 22 May 2026 12:21:20 +0200
-Subject: [PATCH] xmlcatalog: overflow check for large --shell commands
-
-Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124
-
-CVE: CVE-2026-11979
-Signed-off-by: Anton Skorup <anton.skorup@axis.com>
-Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e]
----
- test/catalogs/test.sh | 11 +++++++++++
- xmlcatalog.c | 16 ++++++++++++++++
- 2 files changed, 27 insertions(+)
-
-diff --git a/test/catalogs/test.sh b/test/catalogs/test.sh
-index 7e5eaa76..84e8b90a 100755
---- a/test/catalogs/test.sh
-+++ b/test/catalogs/test.sh
-@@ -10,6 +10,17 @@ fi
-
- exitcode=0
-
-+# Test xmlcatalog --shell command line
-+# Case 1: Really long argument (470 chars)
-+input=""; for i in {1..470}; do input="${input}A"; done
-+echo $input | $xmlcatalog --shell test/catalogs/dockbook.xml || exit 1
-+# Case 2: public + long argument
-+input="public "; for i in {1..470}; do input="${input}A"; done
-+echo $input | $xmlcatalog --shell test/catalogs/dockbook.xml || exit 1
-+# Case 3: public + lots of args
-+input="public "; for i in {1..80}; do input="${input} x"; done
-+echo $input | $xmlcatalog --shell test/catalogs/dockbook.xml || exit 1
-+
- for i in test/catalogs/*.script ; do
- name=$(basename $i .script)
- xml="./test/catalogs/$name.xml"
-diff --git a/xmlcatalog.c b/xmlcatalog.c
-index b400c7cb..5113e930 100644
---- a/xmlcatalog.c
-+++ b/xmlcatalog.c
-@@ -135,6 +135,12 @@ static void usershell(void) {
- (*cur != '\n') && (*cur != '\r')) {
- if (*cur == 0)
- break;
-+ /* Do not read beyond the command array capacity */
-+ if (i >= (int)sizeof(command) - 2) {
-+ printf("Invalid command %s\n", cur);
-+ i = 0;
-+ break;
-+ }
- command[i++] = *cur++;
- }
- command[i] = 0;
-@@ -152,6 +158,11 @@ static void usershell(void) {
- while ((*cur != '\n') && (*cur != '\r') && (*cur != 0)) {
- if (*cur == 0)
- break;
-+ if (i >= (int)sizeof(arg) - 2) {
-+ printf("Invalid arg %s\n", arg);
-+ i = 0;
-+ break;
-+ }
- arg[i++] = *cur++;
- }
- arg[i] = 0;
-@@ -164,6 +175,11 @@ static void usershell(void) {
- cur = arg;
- memset(argv, 0, sizeof(argv));
- while (*cur != 0) {
-+ if (i >= (int)sizeof(argv) / (int)sizeof(char*)) {
-+ printf("Too much arguments\n");
-+ break;
-+ }
-+
- while ((*cur == ' ') || (*cur == '\t')) cur++;
- if (*cur == '\'') {
- cur++;
---
-2.43.0
-
diff --git a/meta/recipes-core/libxml/libxml2_2.15.3.bb b/meta/recipes-core/libxml/libxml2_2.15.4.bb
similarity index 96%
rename from meta/recipes-core/libxml/libxml2_2.15.3.bb
rename to meta/recipes-core/libxml/libxml2_2.15.4.bb
index abf9889b3f3..fc367892bfe 100644
--- a/meta/recipes-core/libxml/libxml2_2.15.3.bb
+++ b/meta/recipes-core/libxml/libxml2_2.15.4.bb
@@ -18,11 +18,10 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt
file://run-ptest \
file://install-tests.patch \
file://0001-Revert-cmake-Fix-installation-directories-in-libxml2.patch \
- file://CVE-2026-11979.patch \
"
-SRC_URI[archive.sha256sum] = "78262a6e7ac170d6528ebfe2efccdf220191a5af6a6cd61ea4a9a9a5042c7a07"
SRC_URI[testtar.sha256sum] = "c6b2d42ee50b8b236e711a97d68e6c4b5c8d83e69a2be4722379f08702ea7273"
+SRC_URI[archive.sha256sum] = "98087fd181d9070724f3fbc65c7377db03038eb92bd882374daff44940138821"
CVE_STATUS[CVE-2025-6170] = "fixed-version: fixed in version 2.14.5"
CVE_STATUS[CVE-2026-6732] = "fixed-version: fixed in version 2.15.3"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 10/79] kbd: Fix CVE-2026-72693
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (8 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 09/79] libxml2: upgrade 2.15.3 -> 2.15.4 Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 11/79] golang: fix homepage Yoann Congal
` (68 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [1]
[1] https://security-tracker.debian.org/tracker/CVE-2026-72693
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-72693
[3] https://access.redhat.com/security/cve/cve-2026-72693
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../recipes-core/kbd/kbd/CVE-2026-72693.patch | 155 ++++++++++++++++++
meta/recipes-core/kbd/kbd_2.9.0.bb | 1 +
2 files changed, 156 insertions(+)
create mode 100644 meta/recipes-core/kbd/kbd/CVE-2026-72693.patch
diff --git a/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch
new file mode 100644
index 00000000000..06b8c195a5a
--- /dev/null
+++ b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch
@@ -0,0 +1,155 @@
+From 78d5ae119742e87baa7dbe0f5c4107e7533fd698 Mon Sep 17 00:00:00 2001
+From: Alexey Gladkov <legion@kernel.org>
+Date: Tue, 12 May 2026 10:20:50 +0200
+Subject: [PATCH] openvt: make -u process matching more conservative
+
+The -u mode relies on the current VT owner to decide which user should
+be used for the new login session. Make that check stricter by requiring
+a matching process owner and controlling terminal instead of relying on
+the ownership of an inherited file descriptor.
+
+Also reject root as a pre-authenticated target and document the tighter
+behavior in the man page.
+
+Signed-off-by: Alexey Gladkov <legion@kernel.org>
+
+Upstream-Status: Backport [https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698]
+CVE: CVE-2026-72693
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ docs/man/man1/openvt.1 | 10 +++++++
+ src/openvt.c | 64 +++++++++++++++++++++++++++++++++++++-----
+ 2 files changed, 67 insertions(+), 7 deletions(-)
+
+diff --git a/docs/man/man1/openvt.1 b/docs/man/man1/openvt.1
+index 8f1244f..404e4a0 100644
+--- a/docs/man/man1/openvt.1
++++ b/docs/man/man1/openvt.1
+@@ -36,6 +36,8 @@ will be made the new current VT.
+ \fB\-u\fR, \fB\-\-user\fR
+ Figure out the owner of the current VT, and run login as that user.
+ Suitable to be called by init. Shouldn't be used with \fI\-c\fR or \fI\-l\fR.
++This option refuses to pre-authenticate root and requires a process owned by
++the VT owner whose controlling terminal is the current VT.
+ .TP
+ \fB\-l\fR, \fB\-\-login\fR
+ Make the command a login shell. A \- is prepended to the name of the command
+@@ -64,6 +66,14 @@ If
+ is compiled with a getopt_long() and you wish to set
+ options to the command to be run, then you must supply
+ the end of options \-\- flag before the command.
++.PP
++The
++.B \-u
++option uses
++.BR "login -f"
++and therefore bypasses normal password authentication for the detected user.
++It is intended only for controlled init or keyboard-request configurations.
++Use a normal authenticated login command when authentication is required.
+ .SH EXAMPLES
+ .B openvt
+ can be used to start a shell on the next free VT, by using the command:
+diff --git a/src/openvt.c b/src/openvt.c
+index a94392b..ddd9239 100644
+--- a/src/openvt.c
++++ b/src/openvt.c
+@@ -57,6 +57,51 @@ usage(int rc, const struct kbd_help *options)
+ exit(rc);
+ }
+
++static int
++proc_pid_stat(const char *pid, uid_t *uid, dev_t *tty)
++{
++ char filename[NAME_MAX + 12];
++ char line[BUFSIZ];
++ char *lp, *rp;
++ FILE *fp;
++ struct stat st;
++ long tty_nr;
++
++ snprintf(filename, sizeof(filename), "/proc/%s/stat", pid);
++ fp = fopen(filename, "r");
++ if (!fp)
++ return -1;
++
++ if (fstat(fileno(fp), &st)) {
++ fclose(fp);
++ return -1;
++ }
++
++ if (!fgets(line, sizeof(line), fp)) {
++ fclose(fp);
++ return -1;
++ }
++ fclose(fp);
++
++ rp = strrchr(line, ')');
++ if (!rp)
++ return -1;
++
++ /*
++ * /proc/<pid>/stat fields after comm are:
++ * state ppid pgrp session tty_nr ...
++ */
++ if (!rp || sscanf(rp + 1, " %*c %*d %*d %*d %ld", &tty_nr) != 1)
++ return -1;
++
++ if (tty_nr <= 0)
++ return -1;
++
++ *uid = st.st_uid;
++ *tty = (dev_t) tty_nr;
++ return 0;
++}
++
+ /*
+ * Support for Spawn_Console: openvt running from init
+ * added by Joshua Spoerri, Thu Jul 18 21:13:16 EDT 1996
+@@ -88,8 +133,7 @@ authenticate_user(int curvt)
+ DIR *dp;
+ struct dirent *dentp;
+ struct stat buf;
+- dev_t console_dev;
+- ino_t console_ino;
++ dev_t console_rdev;
+ uid_t console_uid;
+ char filename[NAME_MAX + 12];
+ struct passwd *pwnam;
+@@ -109,10 +153,12 @@ authenticate_user(int curvt)
+ kbd_error(EXIT_FAILURE, errsv, "%s", filename);
+ }
+ }
+- console_dev = buf.st_dev;
+- console_ino = buf.st_ino;
++ console_rdev = buf.st_rdev;
+ console_uid = buf.st_uid;
+
++ if (console_uid == 0)
++ kbd_error(EXIT_FAILURE, 0, _("Refusing to pre-authenticate root on current tty."));
++
+ /* get the owner of current tty */
+ if (!(pwnam = getpwuid(console_uid)))
+ kbd_error(EXIT_FAILURE, errno, "getpwuid");
+@@ -120,12 +166,16 @@ authenticate_user(int curvt)
+ /* check to make sure that user has a process on that tty */
+ /* this will fail for example when X is running on the tty */
+ while ((dentp = readdir(dp))) {
+- sprintf(filename, "/proc/%s/fd/0", dentp->d_name);
++ uid_t proc_uid;
++ dev_t proc_tty;
++
++ if (dentp->d_name[0] < '0' || dentp->d_name[0] > '9')
++ continue;
+
+- if (stat(filename, &buf))
++ if (proc_pid_stat(dentp->d_name, &proc_uid, &proc_tty) < 0)
+ continue;
+
+- if (buf.st_dev == console_dev && buf.st_ino == console_ino && buf.st_uid == console_uid)
++ if (proc_uid == console_uid && proc_tty == console_rdev)
+ goto got_a_process;
+ }
+
+--
+2.43.0
+
diff --git a/meta/recipes-core/kbd/kbd_2.9.0.bb b/meta/recipes-core/kbd/kbd_2.9.0.bb
index 79b011e529d..06341ba8c04 100644
--- a/meta/recipes-core/kbd/kbd_2.9.0.bb
+++ b/meta/recipes-core/kbd/kbd_2.9.0.bb
@@ -26,6 +26,7 @@ RCONFLICTS:${PN} = "console-tools"
SRC_URI = "${KERNELORG_MIRROR}/linux/utils/${BPN}/${BP}.tar.xz \
file://0001-Preserve-only-necessary-metadata-during-install.patch \
file://0001-libkbdfile-Fix-problem-with-undeclared-sym_gzopen.patch \
+ file://CVE-2026-72693.patch \
"
SRC_URI[sha256sum] = "fb3197f17a99eb44d22a3a1a71f755f9622dd963e66acfdea1a45120951b02ed"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 11/79] golang: fix homepage
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (9 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 10/79] kbd: Fix CVE-2026-72693 Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 12/79] python3-certifi: " Yoann Congal
` (67 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Leading space leads to SPDX document validation errors in some tools.
Example:
SchemaError: \" http://golang.org/\" is not valid under any of the
schemas listed in the 'anyOf' keyword
(components -> ... -> externalReferences -> 0 -> url)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: cbf36f436b477d81b58ff605846a2482308aefa4)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/go/go-binary-native_1.26.7.bb | 2 +-
meta/recipes-devtools/go/go-common.inc | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/meta/recipes-devtools/go/go-binary-native_1.26.7.bb b/meta/recipes-devtools/go/go-binary-native_1.26.7.bb
index 753f1b13bb5..034c051cee7 100644
--- a/meta/recipes-devtools/go/go-binary-native_1.26.7.bb
+++ b/meta/recipes-devtools/go/go-binary-native_1.26.7.bb
@@ -1,7 +1,7 @@
# This recipe is for bootstrapping our go-cross from a prebuilt binary of Go from golang.org.
SUMMARY = "Go programming language compiler (upstream binary for bootstrap)"
-HOMEPAGE = " http://golang.org/"
+HOMEPAGE = "http://golang.org/"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=7998cb338f82d15c0eff93b7004d272a"
diff --git a/meta/recipes-devtools/go/go-common.inc b/meta/recipes-devtools/go/go-common.inc
index 5d0177bdb68..a96e67617b4 100644
--- a/meta/recipes-devtools/go/go-common.inc
+++ b/meta/recipes-devtools/go/go-common.inc
@@ -9,7 +9,7 @@ DESCRIPTION = " The Go programming language is an open source project to make \
fast, statically typed, compiled language that feels like a\
dynamically typed, interpreted language."
-HOMEPAGE = " http://golang.org/"
+HOMEPAGE = "http://golang.org/"
LICENSE = "BSD-3-Clause"
inherit goarch
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 12/79] python3-certifi: fix homepage
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (10 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 11/79] golang: fix homepage Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 13/79] gnutls: fix CVE-2026-5419 Yoann Congal
` (66 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Leading space leads to SPDX document validation errors in some tools.
Example:
SchemaError: \" http://certifi.io/\" is not valid under any of the
schemas listed in the 'anyOf' keyword
(components -> ... -> externalReferences -> 0 -> url)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: ee556d1e1cc16327e0a11207e90ac61d9f1577f3)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-certifi_2026.2.25.bb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/recipes-devtools/python/python3-certifi_2026.2.25.bb b/meta/recipes-devtools/python/python3-certifi_2026.2.25.bb
index 0425f3544fa..fb08bff815f 100644
--- a/meta/recipes-devtools/python/python3-certifi_2026.2.25.bb
+++ b/meta/recipes-devtools/python/python3-certifi_2026.2.25.bb
@@ -2,7 +2,7 @@ SUMMARY = "Python package for providing Mozilla's CA Bundle."
DESCRIPTION = "This installable Python package contains a CA Bundle that you can reference in your \
Python code. This is useful for verifying HTTP requests, for example. This is the same CA Bundle \
which ships with the Requests codebase, and is derived from Mozilla Firefox's canonical set."
-HOMEPAGE = " http://certifi.io/"
+HOMEPAGE = "http://certifi.io/"
LICENSE = "ISC"
LIC_FILES_CHKSUM = "file://LICENSE;md5=11618cb6a975948679286b1211bd573c"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 13/79] gnutls: fix CVE-2026-5419
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (11 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 12/79] python3-certifi: " Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:05 ` [OE-core][wrynose 14/79] sbom-cve-check-update-nvd-native: upgrade 2026.05.07-000006 -> 2026.06.09-000006 Yoann Congal
` (65 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Jakub Szczudlo (Nokia) <jakub.szczudlo@nokia.com>
Backport patch to fix CVE-2026-5419.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-5419
Upstream fix:
https://gitlab.com/gnutls/gnutls/-/commit/1e627aa5ad95c6dc0518d94e9a009997b081a1ab
Tested with ptes
Signed-off-by: Jakub Szczudlo <jakub.szczudlo@nokia.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: fixed patch unneeded changes]
---
.../gnutls/gnutls/CVE-2026-5419.patch | 248 ++++++++++++++++++
meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 +
2 files changed, 249 insertions(+)
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch
diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch
new file mode 100644
index 00000000000..714814eee2c
--- /dev/null
+++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch
@@ -0,0 +1,248 @@
+From 2f3732538d7d8e1ae255ca68c20efc61a1d5b3e2 Mon Sep 17 00:00:00 2001
+From: Daiki Ueno <ueno@gnu.org>
+Date: Fri, 4 Sep 2026 09:17:32 +0000
+Subject: [PATCH] gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free
+
+This tries to make the logic of PKCS#7 padding removal constant-time,
+by removing potential branching operations.
+
+CVE: CVE-2026-5419
+Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/1e627aa5ad95c6dc0518d94e9a009997b081a1ab]
+
+Backport Changes:
+- Adjusted the upstream hunk to match the GnuTLS 3.8.12 code layout.
+- Drop .gitignore from the backport.
+
+Reported-by: Doria Tang of Stony Brook University
+Fixes: #1815
+Fixes: CVE-2026-5419
+Fixes: GNUTLS-SA-2026-04-29-13
+CVSS: 3.7 Low CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
+Signed-off-by: Daiki Ueno <ueno@gnu.org>
+Signed-off-by: Jakub Szczudlo <jakub.szczudlo@nokia.com>
+
+---
+ lib/crypto-api.c | 54 +++++++++++++++++------
+ lib/libgnutls.map | 2 +
+ tests/Makefile.am | 2 +-
+ tests/pkcs7-pad.c | 109 ++++++++++++++++++++++++++++++++++++++++++++++
+ 4 files changed, 153 insertions(+), 14 deletions(-)
+ create mode 100644 tests/pkcs7-pad.c
+
+diff --git a/lib/crypto-api.c b/lib/crypto-api.c
+index 01539d5b52..32143e9de0 100644
+--- a/lib/crypto-api.c
++++ b/lib/crypto-api.c
+@@ -498,6 +498,39 @@ error:
+ return ret;
+ }
+
++/* If succeeds, returns the number of padding bytes to be removed;
++ * zero otherwise.
++ */
++unsigned int _gnutls_pkcs7_unpad(const uint8_t *block, unsigned int block_size)
++{
++ uint8_t padding = block[block_size - 1];
++ volatile unsigned int mask = ~0;
++ volatile unsigned int count = 0;
++
++ /* Count consecutive PADDING bytes from the end, in a
++ * constant-time manner.
++ */
++ for (size_t i = block_size; i > 0; i--) {
++ volatile unsigned int mask2;
++
++ mask2 = -(unsigned int)(block[i - 1] == padding);
++ mask2 &= -(unsigned int)(count < padding);
++
++ /* MASK is initially ~0 and will be flipped to 0 upon first
++ * non-padding bytes.
++ */
++ mask &= mask2;
++ count += 1 & mask;
++ }
++
++ /* PADDING == 0 is effectively excluded here, given COUNT
++ * will never be 0.
++ */
++ mask = -(unsigned int)(count <= block_size);
++ mask &= -(unsigned int)(count == padding);
++ return count & mask;
++}
++
+ /**
+ * gnutls_cipher_decrypt3:
+ * @handle: is a #gnutls_cipher_hd_t type
+@@ -532,22 +565,17 @@ int gnutls_cipher_decrypt3(gnutls_cipher_hd_t handle, const void *ctext,
+ if (_gnutls_cipher_type(h->ctx_enc.e) == CIPHER_BLOCK &&
+ (flags & GNUTLS_CIPHER_PADDING_PKCS7)) {
+ uint8_t *p = ptext;
+- uint8_t padding = p[*ptext_len - 1];
+- if (!padding ||
+- padding > _gnutls_cipher_get_block_size(h->ctx_enc.e)) {
+- return gnutls_assert_val(GNUTLS_E_DECRYPTION_FAILED);
+- }
+- /* Check that the prior bytes are all PADDING */
+- for (size_t i = *ptext_len - padding; i < *ptext_len; i++) {
+- if (padding != p[*ptext_len - 1]) {
+- return gnutls_assert_val(
+- GNUTLS_E_DECRYPTION_FAILED);
+- }
+- }
++ size_t block_size = _gnutls_cipher_get_block_size(h->ctx_enc.e);
++ uint8_t *block = &p[*ptext_len - block_size];
++ unsigned int padding = _gnutls_pkcs7_unpad(block, block_size);
++ volatile unsigned int mask;
++
++ mask = -(unsigned int)(padding == 0);
++ ret = GNUTLS_E_DECRYPTION_FAILED & mask;
+ *ptext_len -= padding;
+ }
+
+- return 0;
++ return ret;
+ }
+
+ /**
+diff --git a/lib/libgnutls.map b/lib/libgnutls.map
+index 955704e..5cc12c8 100644
+--- a/lib/libgnutls.map
++++ b/lib/libgnutls.map
+@@ -1574,4 +1574,6 @@ GNUTLS_PRIVATE_3_4 {
+ _gnutls_pathbuf_append;
+ _gnutls_pathbuf_truncate;
+ _gnutls_pathbuf_deinit;
++ # needed by tests/pkcs7-pad
++ _gnutls_pkcs7_unpad;
+ } GNUTLS_3_4;
+diff --git a/tests/Makefile.am b/tests/Makefile.am
+index ab2685c..1304d2f 100644
+--- a/tests/Makefile.am
++++ b/tests/Makefile.am
+@@ -241,7 +241,7 @@ ctests += mini-record-2 simple gnutls_hmac_fast set_pkcs12_cred cert certuniquei
+ x509cert-dntypes id-on-xmppAddr tls13-compat-mode ciphersuite-name \
+ x509-upnconstraint xts-key-check cipher-padding pkcs7-verify-double-free \
+ fips-rsa-sizes tls12-rehandshake-ticket pathbuf tls-force-ems \
+- psk-importer privkey-derive dh-compute2 ecdh-compute2 \
++ psk-importer privkey-derive dh-compute2 ecdh-compute2 pkcs7-pad \
+ mini-dtls-fragments
+
+ ctests += tls-channel-binding
+diff --git a/tests/pkcs7-pad.c b/tests/pkcs7-pad.c
+new file mode 100644
+index 0000000..d4c3798
+--- /dev/null
++++ b/tests/pkcs7-pad.c
+@@ -0,0 +1,109 @@
++/*
++ * Copyright (C) 2026 Red Hat, Inc.
++ *
++ * This file is part of GnuTLS.
++ *
++ * GnuTLS is free software; you can redistribute it and/or modify it
++ * under the terms of the GNU General Public License as published by
++ * the Free Software Foundation; either version 3 of the License, or
++ * (at your option) any later version.
++ *
++ * GnuTLS is distributed in the hope that it will be useful, but
++ * WITHOUT ANY WARRANTY; without even the implied warranty of
++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
++ * General Public License for more details.
++ *
++ * You should have received a copy of the GNU General Public License
++ * along with GnuTLS. If not, see <https://www.gnu.org/licenses/>.
++ */
++
++/* Test that _gnutls_pkcs7_unpad is branch-free, using valgrind */
++
++#ifdef HAVE_CONFIG_H
++#include "config.h"
++#endif
++
++#include <stdint.h>
++#include <string.h>
++
++#ifdef HAVE_VALGRIND_MEMCHECK_H
++#include <valgrind/memcheck.h>
++#endif
++
++#include "utils.h"
++
++static inline void _gnutls_memory_mark_undefined(void *addr, size_t size)
++{
++#ifdef HAVE_VALGRIND_MEMCHECK_H
++ if (RUNNING_ON_VALGRIND)
++ VALGRIND_MAKE_MEM_UNDEFINED(addr, size);
++#endif
++}
++
++static inline void _gnutls_memory_mark_defined(void *addr, size_t size)
++{
++#ifdef HAVE_VALGRIND_MEMCHECK_H
++ if (RUNNING_ON_VALGRIND)
++ VALGRIND_MAKE_MEM_DEFINED(addr, size);
++#endif
++}
++
++extern unsigned int _gnutls_pkcs7_unpad(const uint8_t *block,
++ unsigned int block_size);
++
++static unsigned int wrap_pkcs7_unpad(uint8_t *block, unsigned int block_size)
++{
++ unsigned int padding;
++
++ _gnutls_memory_mark_undefined(block, block_size);
++
++ padding = _gnutls_pkcs7_unpad(block, block_size);
++
++ _gnutls_memory_mark_defined(block, block_size);
++ _gnutls_memory_mark_defined(&padding, sizeof(padding));
++
++ return padding;
++}
++
++#define PAD 5
++
++void doit(void)
++{
++ uint8_t block[16];
++ unsigned int padding;
++
++ memset(block, 0xFF, sizeof(block));
++ memset(&block[sizeof(block) - PAD], PAD, PAD);
++
++ padding = wrap_pkcs7_unpad(block, sizeof(block));
++ if (padding != PAD)
++ fail("padding should be %d\n", PAD);
++
++ /* The last padding byte exceeds the block size */
++ block[sizeof(block) - 1] = sizeof(block) + 1;
++ padding = wrap_pkcs7_unpad(block, sizeof(block));
++ if (padding != 0)
++ fail("padding should be 0\n");
++ block[sizeof(block) - 1] = PAD;
++
++ /* The last padding byte is zero */
++ block[sizeof(block) - 1] = 0;
++ padding = wrap_pkcs7_unpad(block, sizeof(block));
++ if (padding != 0)
++ fail("padding should be 0\n");
++ block[sizeof(block) - 1] = PAD;
++
++ /* The first padding byte is invalid */
++ block[sizeof(block) - PAD] = PAD + 1;
++ padding = wrap_pkcs7_unpad(block, sizeof(block));
++ if (padding != 0)
++ fail("padding should be 0\n");
++ block[sizeof(block) - PAD] = PAD;
++
++ /* The byte before the first padding equals to PAD */
++ block[sizeof(block) - PAD - 1] = PAD;
++ padding = wrap_pkcs7_unpad(block, sizeof(block));
++ if (padding != PAD)
++ fail("padding should be %d\n", PAD);
++ block[sizeof(block) - PAD - 1] = 0xFF;
++}
+--
+2.43.0
+
diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb
index d513752072c..538fd9c9e0d 100644
--- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb
+++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb
@@ -41,6 +41,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar
file://CVE-2026-42011_p2.patch \
file://CVE-2026-42010.patch \
file://CVE-2026-33845.patch \
+ file://CVE-2026-5419.patch \
"
SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 14/79] sbom-cve-check-update-nvd-native: upgrade 2026.05.07-000006 -> 2026.06.09-000006
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (12 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 13/79] gnutls: fix CVE-2026-5419 Yoann Congal
@ 2026-09-17 22:05 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 15/79] python3-shacl2code: upgrade 1.0.1 -> 1.1.0 Yoann Congal
` (64 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:05 UTC (permalink / raw)
To: openembedded-core
From: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: d33c73535229b5066901faedaaaca0aa6bbd99bf)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...bb => sbom-cve-check-update-nvd-native_2026.06.09-000006.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.05.07-000006.bb => sbom-cve-check-update-nvd-native_2026.06.09-000006.bb} (89%)
diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.05.07-000006.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb
similarity index 89%
rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.05.07-000006.bb
rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb
index 02446e30cee..2917c89e628 100644
--- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.05.07-000006.bb
+++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb
@@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/fkie-cad/nvd-json-data-feeds"
SRC_URI = "git://github.com/fkie-cad/nvd-json-data-feeds.git;branch=main;protocol=https;destsuffix="
SBOM_CVE_CHECK_DB_NAME = "nvd-fkie"
-SRCREV = "72d8841c8ad9083ebf6723063f275444ea0d76f9"
+SRCREV = "7ff4a0622bfdf5313c79635951112d2a45bbe9fd"
UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>.+)"
require sbom-cve-check-update-db.inc
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 15/79] python3-shacl2code: upgrade 1.0.1 -> 1.1.0
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (13 preceding siblings ...)
2026-09-17 22:05 ` [OE-core][wrynose 14/79] sbom-cve-check-update-nvd-native: upgrade 2026.05.07-000006 -> 2026.06.09-000006 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 16/79] python3-spdx-python-model: update from version 0.0.5 to 0.0.6 Yoann Congal
` (63 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Alexander Kanavin <alex@linutronix.de>
Add a patch to python3-spdx-python-model to support this release.
Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: f6557000abc90b0c3b7ca5b4560849e64425c853)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: Changelog: https://github.com/JPEWdev/shacl2code/releases/tag/v1.1.0]
---
...e_1.0.1.bb => python3-shacl2code_1.1.0.bb} | 2 +-
...pdate-shacl2code-to-1.1.0-and-add-ke.patch | 41 +++++++++++++++++++
.../python/python3-spdx-python-model_0.0.5.bb | 10 ++---
3 files changed, 47 insertions(+), 6 deletions(-)
rename meta/recipes-devtools/python/{python3-shacl2code_1.0.1.bb => python3-shacl2code_1.1.0.bb} (81%)
create mode 100644 meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch
diff --git a/meta/recipes-devtools/python/python3-shacl2code_1.0.1.bb b/meta/recipes-devtools/python/python3-shacl2code_1.1.0.bb
similarity index 81%
rename from meta/recipes-devtools/python/python3-shacl2code_1.0.1.bb
rename to meta/recipes-devtools/python/python3-shacl2code_1.1.0.bb
index 904940926fe..a9c8bec84fc 100644
--- a/meta/recipes-devtools/python/python3-shacl2code_1.0.1.bb
+++ b/meta/recipes-devtools/python/python3-shacl2code_1.1.0.bb
@@ -5,7 +5,7 @@ LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=0582f358628f299f29c23bf5fb2f73c9"
PYPI_PACKAGE = "shacl2code"
-SRC_URI[sha256sum] = "c856822b40c330452b8b31e94a658ad4595a5ef03cdb75ea432ea9c73d0cf7d9"
+SRC_URI[sha256sum] = "0f3a243c6482a0f95c5a793288d304908506b51b82dc6133de22be477cd75c24"
inherit pypi python_hatchling
diff --git a/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch b/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch
new file mode 100644
index 00000000000..d9dc0a03c8d
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch
@@ -0,0 +1,41 @@
+From b623473f634aebeb30028cc746fb7a3da4fb2ce3 Mon Sep 17 00:00:00 2001
+From: Arthit Suriyawongkul <arthit@gmail.com>
+Date: Sat, 6 Jun 2026 02:44:48 +0100
+Subject: [PATCH] pyproject.toml: Update shacl2code to 1.1.0 and add keywords
+ (#35)
+
+Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
+Upstream-Status: Backport [https://github.com/spdx/spdx-python-model/commit/2d7b71a7c8e6270a1c8795cdeb4f3dcd9393b3a9]
+Signed-off-by: Alexander Kanavin <alex@linutronix.de>
+---
+ pyproject.toml | 10 +++++++++-
+ 1 file changed, 9 insertions(+), 1 deletion(-)
+
+diff --git a/pyproject.toml b/pyproject.toml
+index c8b3e56..df011e8 100644
+--- a/pyproject.toml
++++ b/pyproject.toml
+@@ -8,6 +8,14 @@ authors = [
+ {name = "Joshua Watt", email = "JPEWhacker@gmail.com"},
+ ]
+ readme = "README.md"
++keywords = [
++ "spdx",
++ "sbom",
++ "spdx3",
++ "software-bill-of-materials",
++ "shacl2code",
++ "bindings",
++]
+ classifiers = [
+ "Development Status :: 4 - Beta",
+ "Intended Audience :: Developers",
+@@ -36,7 +44,7 @@ Issues = "https://github.com/spdx/spdx-python-model/issues"
+ requires = [
+ "hatchling >= 1.27.0",
+ "hatch-build-scripts >= 0.0.4",
+- "shacl2code == 1.0.1",
++ "shacl2code == 1.1.0",
+ ]
+ build-backend = "hatchling.build"
+
diff --git a/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb b/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb
index c77bdffada9..19d9bb815ba 100644
--- a/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb
+++ b/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb
@@ -7,11 +7,11 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=86d3f3a95c324c9479bd8986968f4327"
PYPI_PACKAGE = "spdx_python_model"
SRC_URI[sha256sum] = "4bcf7c6e5e2e8f0b787ed4eb8fb519e2ed776e820cb6d9eb93e44e98eb92ca2d"
-SRC_URI += " \
- https://spdx.org/rdf/3.0.1/spdx-context.jsonld;name=spdx1 \
- https://spdx.org/rdf/3.0.1/spdx-json-serialize-annotations.ttl;name=spdx2 \
- https://spdx.org/rdf/3.0.1/spdx-model.ttl;name=spdx3 \
-"
+SRC_URI += "https://spdx.org/rdf/3.0.1/spdx-context.jsonld;name=spdx1 \
+ https://spdx.org/rdf/3.0.1/spdx-json-serialize-annotations.ttl;name=spdx2 \
+ https://spdx.org/rdf/3.0.1/spdx-model.ttl;name=spdx3 \
+ file://0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch \
+ "
SRC_URI[spdx1.sha256sum] = "c72b0928f094c83e5c127784edb1ebca2af74a104fcacc007c332b23cbc788bd"
SRC_URI[spdx2.sha256sum] = "c6a54b51230eb2bf3b31302546af201f303e0b7931c1db404d7f5b72b6f863e6"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 16/79] python3-spdx-python-model: update from version 0.0.5 to 0.0.6
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (14 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 15/79] python3-shacl2code: upgrade 1.0.1 -> 1.1.0 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 17/79] python3-sbom-cve-check: update to version 1.3.2 Yoann Congal
` (62 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Drop the patch which should no longer be necessary. This is a partial
revert of f6557000abc90b0c3b7ca5b4560849e64425c853
Signed-off-by: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 9b5c92cd6b8ef8a56ebc3815120fd4af5872173c)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: Changelog: https://github.com/spdx/spdx-python-model/releases/tag/v0.0.6]
---
...pdate-shacl2code-to-1.1.0-and-add-ke.patch | 41 -------------------
....bb => python3-spdx-python-model_0.0.6.bb} | 12 +++---
2 files changed, 6 insertions(+), 47 deletions(-)
delete mode 100644 meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch
rename meta/recipes-devtools/python/{python3-spdx-python-model_0.0.5.bb => python3-spdx-python-model_0.0.6.bb} (72%)
diff --git a/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch b/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch
deleted file mode 100644
index d9dc0a03c8d..00000000000
--- a/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch
+++ /dev/null
@@ -1,41 +0,0 @@
-From b623473f634aebeb30028cc746fb7a3da4fb2ce3 Mon Sep 17 00:00:00 2001
-From: Arthit Suriyawongkul <arthit@gmail.com>
-Date: Sat, 6 Jun 2026 02:44:48 +0100
-Subject: [PATCH] pyproject.toml: Update shacl2code to 1.1.0 and add keywords
- (#35)
-
-Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
-Upstream-Status: Backport [https://github.com/spdx/spdx-python-model/commit/2d7b71a7c8e6270a1c8795cdeb4f3dcd9393b3a9]
-Signed-off-by: Alexander Kanavin <alex@linutronix.de>
----
- pyproject.toml | 10 +++++++++-
- 1 file changed, 9 insertions(+), 1 deletion(-)
-
-diff --git a/pyproject.toml b/pyproject.toml
-index c8b3e56..df011e8 100644
---- a/pyproject.toml
-+++ b/pyproject.toml
-@@ -8,6 +8,14 @@ authors = [
- {name = "Joshua Watt", email = "JPEWhacker@gmail.com"},
- ]
- readme = "README.md"
-+keywords = [
-+ "spdx",
-+ "sbom",
-+ "spdx3",
-+ "software-bill-of-materials",
-+ "shacl2code",
-+ "bindings",
-+]
- classifiers = [
- "Development Status :: 4 - Beta",
- "Intended Audience :: Developers",
-@@ -36,7 +44,7 @@ Issues = "https://github.com/spdx/spdx-python-model/issues"
- requires = [
- "hatchling >= 1.27.0",
- "hatch-build-scripts >= 0.0.4",
-- "shacl2code == 1.0.1",
-+ "shacl2code == 1.1.0",
- ]
- build-backend = "hatchling.build"
-
diff --git a/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb b/meta/recipes-devtools/python/python3-spdx-python-model_0.0.6.bb
similarity index 72%
rename from meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb
rename to meta/recipes-devtools/python/python3-spdx-python-model_0.0.6.bb
index 19d9bb815ba..def12b20492 100644
--- a/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb
+++ b/meta/recipes-devtools/python/python3-spdx-python-model_0.0.6.bb
@@ -5,13 +5,13 @@ LICENSE = "Apache-2.0"
LIC_FILES_CHKSUM = "file://LICENSE;md5=86d3f3a95c324c9479bd8986968f4327"
PYPI_PACKAGE = "spdx_python_model"
-SRC_URI[sha256sum] = "4bcf7c6e5e2e8f0b787ed4eb8fb519e2ed776e820cb6d9eb93e44e98eb92ca2d"
+SRC_URI[sha256sum] = "f1938eb08d08218278122849bba123b8993a0171e9b4f5ea6af7aeb71f3204d7"
-SRC_URI += "https://spdx.org/rdf/3.0.1/spdx-context.jsonld;name=spdx1 \
- https://spdx.org/rdf/3.0.1/spdx-json-serialize-annotations.ttl;name=spdx2 \
- https://spdx.org/rdf/3.0.1/spdx-model.ttl;name=spdx3 \
- file://0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch \
- "
+SRC_URI += " \
+ https://spdx.org/rdf/3.0.1/spdx-context.jsonld;name=spdx1 \
+ https://spdx.org/rdf/3.0.1/spdx-json-serialize-annotations.ttl;name=spdx2 \
+ https://spdx.org/rdf/3.0.1/spdx-model.ttl;name=spdx3 \
+"
SRC_URI[spdx1.sha256sum] = "c72b0928f094c83e5c127784edb1ebca2af74a104fcacc007c332b23cbc788bd"
SRC_URI[spdx2.sha256sum] = "c6a54b51230eb2bf3b31302546af201f303e0b7931c1db404d7f5b72b6f863e6"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 17/79] python3-sbom-cve-check: update to version 1.3.2
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (15 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 16/79] python3-spdx-python-model: update from version 0.0.5 to 0.0.6 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 18/79] sbom-cve-check-update-cvelist-native: update to version 2026-06-24 Yoann Congal
` (61 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
For details on this new release, see:
https://github.com/bootlin/sbom-cve-check/releases/tag/v1.3.2
Signed-off-by: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: cd6313d94ac221dc37c30ffec8c83b6c8d1deeff)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...-sbom-cve-check_1.3.1.bb => python3-sbom-cve-check_1.3.2.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/sbom-cve-check/{python3-sbom-cve-check_1.3.1.bb => python3-sbom-cve-check_1.3.2.bb} (82%)
diff --git a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.1.bb b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb
similarity index 82%
rename from meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.1.bb
rename to meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb
index 8120848a667..f14901e3008 100644
--- a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.1.bb
+++ b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb
@@ -5,7 +5,7 @@ LICENSE = "GPL-2.0-or-later"
LIC_FILES_CHKSUM = "file://LICENSE;md5=570a9b3749dd0463a1778803b12a6dce"
PYPI_PACKAGE = "sbom_cve_check"
-SRC_URI[sha256sum] = "675828b2f02f11620b7a229853a24d09264bf41161be5fbb80a92456f46a14e0"
+SRC_URI[sha256sum] = "0a7f07a0c6ce45d40adc6d311ddc25c4466f59bafcbce149b6fb3663791a5d89"
inherit pypi python_hatchling
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 18/79] sbom-cve-check-update-cvelist-native: update to version 2026-06-24
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (16 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 17/79] python3-sbom-cve-check: update to version 1.3.2 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 19/79] sbom-cve-check-update-nvd-native: update to version 2026.06.24-000003 Yoann Congal
` (60 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Update cvelistV5 to the CVE database from 2026-06-24.
Signed-off-by: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: f7a706321eb783ad43d8d9666ea3536024cb5be8)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...07.bb => sbom-cve-check-update-cvelist-native_2026-06-24.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-cvelist-native_2026-05-07.bb => sbom-cve-check-update-cvelist-native_2026-06-24.bb} (89%)
diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-05-07.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb
similarity index 89%
rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-05-07.bb
rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb
index 7670172c40b..ca192bc9cf3 100644
--- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-05-07.bb
+++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb
@@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/CVEProject/cvelistV5"
SRC_URI = "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https;destsuffix="
SBOM_CVE_CHECK_DB_NAME = "cvelist"
-SRCREV = "dd0e93c75034d0167498174c886a56729edc44de"
+SRCREV = "966bddf787997b471325e065cae82702a60c64ff"
UPSTREAM_CHECK_GITTAGREGEX = "(?P<pver>.+)_baseline"
require sbom-cve-check-update-db.inc
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 19/79] sbom-cve-check-update-nvd-native: update to version 2026.06.24-000003
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (17 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 18/79] sbom-cve-check-update-cvelist-native: update to version 2026-06-24 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 20/79] sbom-cve-check-update-cvelist-native: -> 2026-07-23 Yoann Congal
` (59 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Update fkie-cad/nvd-json-data-feeds to the CVE database from 2026-06-24.
Signed-off-by: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: fba290297e9bbc8c6c4086e7784ece5d06dbd26d)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...bb => sbom-cve-check-update-nvd-native_2026.06.24-000003.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.06.09-000006.bb => sbom-cve-check-update-nvd-native_2026.06.24-000003.bb} (89%)
diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb
similarity index 89%
rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb
rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb
index 2917c89e628..73d9e776929 100644
--- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb
+++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb
@@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/fkie-cad/nvd-json-data-feeds"
SRC_URI = "git://github.com/fkie-cad/nvd-json-data-feeds.git;branch=main;protocol=https;destsuffix="
SBOM_CVE_CHECK_DB_NAME = "nvd-fkie"
-SRCREV = "7ff4a0622bfdf5313c79635951112d2a45bbe9fd"
+SRCREV = "11e62eba27133a54836b7a081d05ff96f72d879b"
UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>.+)"
require sbom-cve-check-update-db.inc
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 20/79] sbom-cve-check-update-cvelist-native: -> 2026-07-23
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (18 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 19/79] sbom-cve-check-update-nvd-native: update to version 2026.06.24-000003 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 21/79] sbom-cve-check-update-nvd-native: -> 2026.07.23-000007 Yoann Congal
` (58 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <ticotimo@gmail.com>
The diff is quite large, but a partial comparison can be seen:
https://github.com/CVEProject/cvelistV5/compare/2026-06-24_baseline..2026-07-23_baseline
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 1323691ceab2a338c4d5b9c15624b8d22c472e7f)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...24.bb => sbom-cve-check-update-cvelist-native_2026-07-23.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-cvelist-native_2026-06-24.bb => sbom-cve-check-update-cvelist-native_2026-07-23.bb} (89%)
diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb
similarity index 89%
rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb
rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb
index ca192bc9cf3..0e664d89e07 100644
--- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb
+++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb
@@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/CVEProject/cvelistV5"
SRC_URI = "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https;destsuffix="
SBOM_CVE_CHECK_DB_NAME = "cvelist"
-SRCREV = "966bddf787997b471325e065cae82702a60c64ff"
+SRCREV = "7a274ec07043f54c07d0a3b5c7fc89ba5793f023"
UPSTREAM_CHECK_GITTAGREGEX = "(?P<pver>.+)_baseline"
require sbom-cve-check-update-db.inc
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 21/79] sbom-cve-check-update-nvd-native: -> 2026.07.23-000007
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (19 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 20/79] sbom-cve-check-update-cvelist-native: -> 2026-07-23 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 22/79] python3-sbom-cve-check: update to version 1.3.3 Yoann Congal
` (57 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <ticotimo@gmail.com>
The diff is quite large, but a partial comparison can be seen:
https://github.com/fkie-cad/nvd-json-data-feeds/compare/v2026.06.24-000003..v2026.07.23-000007
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 9d89b3b802bab144afa30e03b0411ae58232ef11)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...bb => sbom-cve-check-update-nvd-native_2026.07.23-000007.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.06.24-000003.bb => sbom-cve-check-update-nvd-native_2026.07.23-000007.bb} (89%)
diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb
similarity index 89%
rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb
rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb
index 73d9e776929..cf35b169235 100644
--- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb
+++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb
@@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/fkie-cad/nvd-json-data-feeds"
SRC_URI = "git://github.com/fkie-cad/nvd-json-data-feeds.git;branch=main;protocol=https;destsuffix="
SBOM_CVE_CHECK_DB_NAME = "nvd-fkie"
-SRCREV = "11e62eba27133a54836b7a081d05ff96f72d879b"
+SRCREV = "64a0cea215628d780438fba8bfe0f3300db1b702"
UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>.+)"
require sbom-cve-check-update-db.inc
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 22/79] python3-sbom-cve-check: update to version 1.3.3
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (20 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 21/79] sbom-cve-check-update-nvd-native: -> 2026.07.23-000007 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 23/79] sbom-cve-check-update-cvelist-native: update to version 2026-08-03 Yoann Congal
` (56 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Benjamin Robin <benjamin.robin@bootlin.com>
For details on this new release, see:
https://github.com/bootlin/sbom-cve-check/releases/tag/v1.3.3
Signed-off-by: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 7feb4e30ba17a4b0eb37a1c6dde671d4491bd35d)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC:
Noticeable change:
Generate a "not affected" assessment if the vulnerability is disputed
]
---
...-sbom-cve-check_1.3.2.bb => python3-sbom-cve-check_1.3.3.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/sbom-cve-check/{python3-sbom-cve-check_1.3.2.bb => python3-sbom-cve-check_1.3.3.bb} (82%)
diff --git a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb
similarity index 82%
rename from meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb
rename to meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb
index f14901e3008..2aca1005694 100644
--- a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb
+++ b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb
@@ -5,7 +5,7 @@ LICENSE = "GPL-2.0-or-later"
LIC_FILES_CHKSUM = "file://LICENSE;md5=570a9b3749dd0463a1778803b12a6dce"
PYPI_PACKAGE = "sbom_cve_check"
-SRC_URI[sha256sum] = "0a7f07a0c6ce45d40adc6d311ddc25c4466f59bafcbce149b6fb3663791a5d89"
+SRC_URI[sha256sum] = "8b766be1ae92b4eceaa2f694dd4724e310886c6436f44267a6bbc6a7b81ab8b9"
inherit pypi python_hatchling
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 23/79] sbom-cve-check-update-cvelist-native: update to version 2026-08-03
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (21 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 22/79] python3-sbom-cve-check: update to version 1.3.3 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 24/79] sbom-cve-check-update-nvd-native: update to version 2026.08.03-000011 Yoann Congal
` (55 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Benjamin Robin <benjamin.robin@bootlin.com>
Update cvelistV5 to the CVE database from 2026-08-03.
Signed-off-by: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 25e68deb8178f7021605a39fa85acea04a375372)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...23.bb => sbom-cve-check-update-cvelist-native_2026-08-03.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-cvelist-native_2026-07-23.bb => sbom-cve-check-update-cvelist-native_2026-08-03.bb} (89%)
diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-03.bb
similarity index 89%
rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb
rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-03.bb
index 0e664d89e07..aa21b06953e 100644
--- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb
+++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-03.bb
@@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/CVEProject/cvelistV5"
SRC_URI = "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https;destsuffix="
SBOM_CVE_CHECK_DB_NAME = "cvelist"
-SRCREV = "7a274ec07043f54c07d0a3b5c7fc89ba5793f023"
+SRCREV = "b160e6f2915ac726b29ee0689fc920f5016abef5"
UPSTREAM_CHECK_GITTAGREGEX = "(?P<pver>.+)_baseline"
require sbom-cve-check-update-db.inc
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 24/79] sbom-cve-check-update-nvd-native: update to version 2026.08.03-000011
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (22 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 23/79] sbom-cve-check-update-cvelist-native: update to version 2026-08-03 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 25/79] python3-mako: correct CVE_PRODUCT mapping Yoann Congal
` (54 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Benjamin Robin <benjamin.robin@bootlin.com>
Update fkie-cad/nvd-json-data-feeds to the CVE database from 2026.08.03.
Signed-off-by: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 5928cf1985d65b5dc7a909df596d7ff91533fccd)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...bb => sbom-cve-check-update-nvd-native_2026.08.03-000011.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.07.23-000007.bb => sbom-cve-check-update-nvd-native_2026.08.03-000011.bb} (89%)
diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.03-000011.bb
similarity index 89%
rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb
rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.03-000011.bb
index cf35b169235..720b5ded0ac 100644
--- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb
+++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.03-000011.bb
@@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/fkie-cad/nvd-json-data-feeds"
SRC_URI = "git://github.com/fkie-cad/nvd-json-data-feeds.git;branch=main;protocol=https;destsuffix="
SBOM_CVE_CHECK_DB_NAME = "nvd-fkie"
-SRCREV = "64a0cea215628d780438fba8bfe0f3300db1b702"
+SRCREV = "b9f52bb052695dac5cabbd58e049eaac73697161"
UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>.+)"
require sbom-cve-check-update-db.inc
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 25/79] python3-mako: correct CVE_PRODUCT mapping
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (23 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 24/79] sbom-cve-check-update-nvd-native: update to version 2026.08.03-000011 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 26/79] recipeutils: add optional stable_upgrade parameter to get_recipe_upgrade_status Yoann Congal
` (53 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
The inherited "python:mako" mapping is not used for the packaged Mako
source and causes its vulnerability records to be missed.
Use "makotemplates:mako" for its historical NVD configuration identity
and "sqlalchemy:mako" for the current NVD dictionary CPE, NVD
configuration, and CNA affected-data identity.
Backport note: this applies the metadata to Wrynose Mako 1.3.10 rather
than master 1.4.1; the older release exposes applicable unpatched records.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 76fc2046d3f251af34dd04f8fdcfc0c1d6016380)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-mako_1.3.12.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-mako_1.3.12.bb b/meta/recipes-devtools/python/python3-mako_1.3.12.bb
index b2c1a8dad8d..48f660870e7 100644
--- a/meta/recipes-devtools/python/python3-mako_1.3.12.bb
+++ b/meta/recipes-devtools/python/python3-mako_1.3.12.bb
@@ -10,6 +10,8 @@ inherit pypi python_setuptools_build_meta ptest-python-pytest
SRC_URI[sha256sum] = "9f778e93289bd410bb35daadeb4fc66d95a746f0b75777b942088b7fd7af550a"
+CVE_PRODUCT = "makotemplates:mako sqlalchemy:mako"
+
RDEPENDS:${PN} = "python3-html \
python3-markupsafe \
python3-misc \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 26/79] recipeutils: add optional stable_upgrade parameter to get_recipe_upgrade_status
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (24 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 25/79] python3-mako: correct CVE_PRODUCT mapping Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 27/79] lib/oe/recipeutils: make stable_upgrade argument optional in get_recipe_upstream_version() Yoann Congal
` (52 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Chen Qi <Qi.Chen@windriver.com>
We want the ability to do stable version upgrades for recipes.
To this end, add an optional stable_upgrade parameter to the
get_recipe_upgrade_status function, which defaults to False and
when enabled will try to get the latest stable version of the recipe.
The UPSTREAM_STABLE_RELEASE_REGEX is respected. If a recipe sets
it, it will be used as the filter_regex. If it's not set explicitly,
it means that there's no stable updates or the recipe hasn't been
checked yet.
Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 1ed8fdda035dcc21f3df71c0c996973224f4f683)
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/lib/oe/recipeutils.py | 23 +++++++++++++++++------
1 file changed, 17 insertions(+), 6 deletions(-)
diff --git a/meta/lib/oe/recipeutils.py b/meta/lib/oe/recipeutils.py
index c6604f536db..7c1df518a8d 100644
--- a/meta/lib/oe/recipeutils.py
+++ b/meta/lib/oe/recipeutils.py
@@ -1009,7 +1009,7 @@ def get_recipe_pv_with_pfx_sfx(pv, uri_type):
return (pv, pfx, sfx)
-def get_recipe_upstream_version(rd):
+def get_recipe_upstream_version(rd, stable_upgrade):
"""
Get upstream version of recipe using bb.fetch2 methods with support for
http, https, ftp and git.
@@ -1080,7 +1080,15 @@ def get_recipe_upstream_version(rd):
except bb.fetch2.FetchError as e:
bb.warn("Unable to obtain latest revision: {}".format(e))
else:
- pupver = ud.method.latest_versionstring(ud, rd)
+ if stable_upgrade:
+ stable_release_regex = rd.getVar("UPSTREAM_STABLE_RELEASE_REGEX")
+ if stable_release_regex:
+ pupver = ud.method.latest_versionstring(ud, rd, filter_regex=stable_release_regex)
+ else:
+ # Not explicitly setting "UPSTREAM_STABLE_RELEASE_REGEX" means there's no stable upgrade
+ pupver = (ru['current_version'], None)
+ else:
+ pupver = ud.method.latest_versionstring(ud, rd)
(upversion, revision) = pupver
if upversion:
@@ -1094,8 +1102,8 @@ def get_recipe_upstream_version(rd):
return ru
-def _get_recipe_upgrade_status(data):
- uv = get_recipe_upstream_version(data)
+def _get_recipe_upgrade_status(data, stable_upgrade):
+ uv = get_recipe_upstream_version(data, stable_upgrade)
pn = data.getVar('PN')
cur_ver = uv['current_version']
@@ -1119,9 +1127,10 @@ def _get_recipe_upgrade_status(data):
return {'pn':pn, 'status':status, 'cur_ver':cur_ver, 'next_ver':next_ver, 'maintainer':maintainer, 'revision':revision, 'no_upgrade_reason':no_upgrade_reason}
-def get_recipe_upgrade_status(recipes=None):
+def get_recipe_upgrade_status(recipes=None, stable_upgrade=False):
pkgs_list = []
data_copy_list = []
+ stable_copy_list = []
copy_vars = ('SRC_URI',
'PV',
'DL_DIR',
@@ -1134,6 +1143,7 @@ def get_recipe_upgrade_status(recipes=None):
'UPSTREAM_CHECK_REGEX',
'UPSTREAM_CHECK_URI',
'UPSTREAM_VERSION_UNKNOWN',
+ 'UPSTREAM_STABLE_RELEASE_REGEX',
'RECIPE_MAINTAINER',
'RECIPE_NO_UPDATE_REASON',
'RECIPE_UPSTREAM_VERSION',
@@ -1180,12 +1190,13 @@ def get_recipe_upgrade_status(recipes=None):
data_copy.setVar(k, data.getVar(k))
data_copy_list.append(data_copy)
+ stable_copy_list.append(stable_upgrade)
recipeincludes[data.getVar('FILE')] = {'bbincluded':data.getVar('BBINCLUDED').split(),'pn':data.getVar('PN')}
from concurrent.futures import ProcessPoolExecutor
with ProcessPoolExecutor(max_workers=utils.cpu_count()) as executor:
- pkgs_list = executor.map(_get_recipe_upgrade_status, data_copy_list)
+ pkgs_list = executor.map(_get_recipe_upgrade_status, data_copy_list, stable_copy_list)
return _group_recipes(pkgs_list, _get_common_include_recipes(recipeincludes))
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 27/79] lib/oe/recipeutils: make stable_upgrade argument optional in get_recipe_upstream_version()
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (25 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 26/79] recipeutils: add optional stable_upgrade parameter to get_recipe_upgrade_status Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 28/79] upstream-stable-release-point.bbclass: add bbclass for stable point upgrade Yoann Congal
` (51 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Ross Burton <ross.burton@arm.com>
The change[1] that added the stable_upgrade argument made it optional
for the high-level get_recipe_upgrade_status() function, but not
get_recipe_upstream_version().
This function is exposed API so be kind to users and also make it an
optional argument there.
[1] oe-core 1ed8fdda035 ("recipeutils: add optional stable_upgrade parameter to get_recipe_upgrade_status")
Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 6f8ae1ecf38d85fe4464bef2954a86b6dc4f059c)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/lib/oe/recipeutils.py | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/lib/oe/recipeutils.py b/meta/lib/oe/recipeutils.py
index 7c1df518a8d..64bf2f950f8 100644
--- a/meta/lib/oe/recipeutils.py
+++ b/meta/lib/oe/recipeutils.py
@@ -1009,7 +1009,7 @@ def get_recipe_pv_with_pfx_sfx(pv, uri_type):
return (pv, pfx, sfx)
-def get_recipe_upstream_version(rd, stable_upgrade):
+def get_recipe_upstream_version(rd, stable_upgrade=False):
"""
Get upstream version of recipe using bb.fetch2 methods with support for
http, https, ftp and git.
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 28/79] upstream-stable-release-point.bbclass: add bbclass for stable point upgrade
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (26 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 27/79] lib/oe/recipeutils: make stable_upgrade argument optional in get_recipe_upstream_version() Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 29/79] devtool/upgrade.py: add --stable option Yoann Congal
` (50 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Chen Qi <Qi.Chen@windriver.com>
If a recipe can do stable version upgrade and the stable parts of the version
is seperated by '.', then it can inherit this bbclass.
By default, the stable parts number is 2, which means the following upgrades
are stable version upgrades:
x.y.z -> x.y.z+1
x.y.z+1 -> x.y.z+1.zz
x.y.z+1.zz -> x.y.z+2
Recipes that have different stable version parts can also inherit this bbclass
and set STABLE_VERSION_PARTS. For example, systemd sets this variable to "1".
For recipes whose stable version part is not separated by '.', they should not
inherit this bbclass and intead set UPSTREAM_STABLE_RELEASE_REGEX themselves.
For example, openssh's stable part is separted by 'p' and should not inherit
this bbclass.
Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit a1e069d04cb13e990b362804bd56a4935338ef96)
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../upstream-stable-release-point.bbclass | 21 +++++++++++++++++++
1 file changed, 21 insertions(+)
create mode 100644 meta/classes-recipe/upstream-stable-release-point.bbclass
diff --git a/meta/classes-recipe/upstream-stable-release-point.bbclass b/meta/classes-recipe/upstream-stable-release-point.bbclass
new file mode 100644
index 00000000000..98fdb5b808e
--- /dev/null
+++ b/meta/classes-recipe/upstream-stable-release-point.bbclass
@@ -0,0 +1,21 @@
+#
+# Copyright OpenEmbedded Contributors
+#
+# SPDX-License-Identifier: MIT
+#
+
+#
+# This bbclass is expected to be inherited by recipes explicitly.
+# If a recipe's version is separated by point and we know for sure
+# which parts of the version represent the stable part, then the
+# recipe could inherit this bbclass.
+#
+
+STABLE_VERSION_PARTS ?= "2"
+def get_majmin_version_regex(d):
+ pv = d.getVar('PV')
+ stable_parts = pv.split('.')[:int(d.getVar('STABLE_VERSION_PARTS'))]
+ return r'\.'.join(stable_parts)
+
+STABLE_VERSION_REGEX = "${@get_majmin_version_regex(d)}"
+UPSTREAM_STABLE_RELEASE_REGEX ?= "^${STABLE_VERSION_REGEX}(\.\d+)*$"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 29/79] devtool/upgrade.py: add --stable option
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (27 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 28/79] upstream-stable-release-point.bbclass: add bbclass for stable point upgrade Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 30/79] systemd: inherit upstream-stable-release-point Yoann Congal
` (49 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Chen Qi <Qi.Chen@windriver.com>
Add '--stable' option to the three subcommands:
- latest-version
- check-upgrade-status
- upgrade
The effect of this option is to make the subcommand only consider
stable releases.
Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
(cherry picked from commit 1e86aa039108621b2af734ef358a1e9d3c4d88d8)
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
scripts/lib/devtool/upgrade.py | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/scripts/lib/devtool/upgrade.py b/scripts/lib/devtool/upgrade.py
index 8930fde5d66..91cb85403c4 100644
--- a/scripts/lib/devtool/upgrade.py
+++ b/scripts/lib/devtool/upgrade.py
@@ -560,7 +560,7 @@ def upgrade(args, config, basepath, workspace):
# try to automatically discover latest version and revision if not provided on command line
if not args.version and not args.srcrev:
- version_info = oe.recipeutils.get_recipe_upstream_version(rd)
+ version_info = oe.recipeutils.get_recipe_upstream_version(rd, args.stable)
if version_info['version'] and not version_info['version'].endswith("new-commits-available"):
args.version = version_info['version']
if version_info['revision']:
@@ -626,7 +626,7 @@ def latest_version(args, config, basepath, workspace):
rd = parse_recipe(config, tinfoil, args.recipename, True)
if not rd:
return 1
- version_info = oe.recipeutils.get_recipe_upstream_version(rd)
+ version_info = oe.recipeutils.get_recipe_upstream_version(rd, args.stable)
# "new-commits-available" is an indication that upstream never issues version tags
if not version_info['version'].endswith("new-commits-available"):
logger.info("Current version: {}".format(version_info['current_version']))
@@ -649,7 +649,7 @@ def check_upgrade_status(args, config, basepath, workspace):
"cannot be updated due to: %s" %(recipe['no_upgrade_reason']) if recipe['no_upgrade_reason'] else ""))
if not args.recipe:
logger.info("Checking the upstream status for all recipes may take a few minutes")
- results = oe.recipeutils.get_recipe_upgrade_status(args.recipe)
+ results = oe.recipeutils.get_recipe_upgrade_status(args.recipe, args.stable)
for recipegroup in results:
upgrades = [r for r in recipegroup if r['status'] != 'MATCH']
currents = [r for r in recipegroup if r['status'] == 'MATCH']
@@ -673,6 +673,7 @@ def register_commands(subparsers, context):
group='starting')
parser_upgrade.add_argument('recipename', help='Name of recipe to upgrade (just name - no version, path or extension)')
parser_upgrade.add_argument('srctree', nargs='?', help='Path to where to extract the source tree. If not specified, a subdirectory of %s will be used.' % defsrctree)
+ parser_upgrade.add_argument('--stable', action="store_true", help='Only consider stable upstream releases')
parser_upgrade.add_argument('--version', '-V', help='Version to upgrade to (PV). If omitted, latest upstream version will be determined and used, if possible.')
parser_upgrade.add_argument('--srcrev', '-S', help='Source revision to upgrade to (useful when fetching from an SCM such as git)')
parser_upgrade.add_argument('--srcbranch', '-B', help='Branch in source repository containing the revision to use (if fetching from an SCM such as git)')
@@ -690,11 +691,13 @@ def register_commands(subparsers, context):
description='Queries the upstream server for what the latest upstream release is (for git, tags are checked, for tarballs, a list of them is obtained, and one with the highest version number is reported)',
group='info')
parser_latest_version.add_argument('recipename', help='Name of recipe to query (just name - no version, path or extension)')
+ parser_latest_version.add_argument('--stable', action="store_true", help='Only consider stable upstream releases')
parser_latest_version.set_defaults(func=latest_version)
parser_check_upgrade_status = subparsers.add_parser('check-upgrade-status', help="Report upgradability for multiple (or all) recipes",
description="Prints a table of recipes together with versions currently provided by recipes, and latest upstream versions, when there is a later version available",
group='info')
parser_check_upgrade_status.add_argument('recipe', help='Name of the recipe to report (omit to report upgrade info for all recipes)', nargs='*')
+ parser_check_upgrade_status.add_argument('--stable', action="store_true", help='Only consider stable upstream releases')
parser_check_upgrade_status.add_argument('--all', '-a', help='Show all recipes, not just recipes needing upgrade', action="store_true")
parser_check_upgrade_status.set_defaults(func=check_upgrade_status)
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 30/79] systemd: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (28 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 29/79] devtool/upgrade.py: add --stable option Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 31/79] glib-2.0: " Yoann Congal
` (48 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
systemd's README ("STABLE BRANCHES AND BACKPORTS") documents per-release
stable branches carrying backported patches. The current one, v261-stable,
is branched in the main repository; the README still points at the
systemd-stable repository, which holds the branches up to v255. The major
is a single version part (261 -> 261.1), so upgrades within a major
are stable point upgrades per the OE-Core stable release policy
(ref-manual, "Stable Point Release Upgrades"). STABLE_VERSION_PARTS is
set to 1 accordingly.
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/systemd/systemd/blob/v261.1/README#L460
https://github.com/systemd/systemd/tree/v261-stable
Checked the last point release for feature creep:
261.2 (Jul 23 2026), against 261.1 (Jun 26 2026): 277 commits, mostly
fixes. NEWS files both releases under "CHANGES WITH 261" and gives
neither its own entry. Four items are feature-shaped: refcounting,
argument handling and JSON output additions, plus one new internal
string-util flag.
Those are small internal additions on a real, diverged stable branch
rather than mainline drift, and none introduce a new subsystem: closer in
scope to a security-hardening batch than a feature release, though
broader than a pure bugfix release.
These bumps are not free: the scarthgap 255.4 -> 255.13 bump was held for a
v2 because TCLIBC=musl broke, and was merged once fixed. A point release
being fixes-only upstream does not remove the need to build and test it.
Already tracked this way on the OE stable branches, counting only bumps
made since each branch forked from master: kirkstone 250.4 -> 250.14 and
scarthgap 255.4 -> 255.21. wrynose has had no point-release bump yet.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit c19dd5b2afa61ca78dad0b65556ba66e83db57c5)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-core/systemd/systemd.inc | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/meta/recipes-core/systemd/systemd.inc b/meta/recipes-core/systemd/systemd.inc
index f107c4c5da5..bbcacf9deb5 100644
--- a/meta/recipes-core/systemd/systemd.inc
+++ b/meta/recipes-core/systemd/systemd.inc
@@ -21,6 +21,11 @@ SRC_URI = "git://github.com/systemd/systemd.git;protocol=https;branch=${SRCBRANC
CVE_PRODUCT = "systemd"
+# systemd publishes bugfix/security-only releases on its stable/v<major>-stable
+# branches (e.g. 261 -> 261.1). The major is a single version part.
+STABLE_VERSION_PARTS = "1"
+inherit upstream-stable-release-point
+
CVE_STATUS[CVE-2019-3815] = "not-applicable-platform: only applied to RHEL"
CVE_STATUS[CVE-2026-40223] = "fixed-version: fixed in 259.2"
CVE_STATUS[CVE-2026-40224] = "fixed-version: fixed in 259.3"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 31/79] glib-2.0: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (29 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 30/79] systemd: inherit upstream-stable-release-point Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 32/79] dbus: " Yoann Congal
` (47 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
GLib's docs/backports.md states that only bug and documentation fixes are
backported to the current stable branch, that new features and API/ABI
changes must not be, and that micro stable releases are intended as
drop-in replacements. So upgrades within a major.minor are stable point
upgrades per the OE-Core stable release policy (ref-manual, "Stable Point
Release Upgrades").
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://gitlab.gnome.org/GNOME/glib/-/blob/2.88.2/docs/backports.md#L18
Checked the last two point releases for feature creep:
2.88.2 (Jun 25 2026): entirely "Bugs fixed" backports plus translation
updates.
2.88.1 (May 02 2026): seven fixes -- a GCC 16 miscompilation, a GRegex
out-of-bounds read with security impact, and five further out-of-bounds
reads. No API or behaviour changes.
The series opened with 2.88.0 (Mar 16 2026), which must stay outside the
regex as the feature-level release.
Already tracked this way on the OE stable branches, counting only bumps
made since each branch forked from master: kirkstone 2.72.0 -> 2.72.3,
scarthgap 2.78.4 -> 2.78.6, and wrynose 2.88.0 -> 2.88.2.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 8de7017a3161ffb04f36e9c6ba2f7ead402dc4a5)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-core/glib-2.0/glib.inc | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/meta/recipes-core/glib-2.0/glib.inc b/meta/recipes-core/glib-2.0/glib.inc
index d49ae131685..cad74f53f71 100644
--- a/meta/recipes-core/glib-2.0/glib.inc
+++ b/meta/recipes-core/glib-2.0/glib.inc
@@ -30,7 +30,9 @@ LEAD_SONAME = "libglib-2.0.*"
GNOMEBN = "glib"
-inherit gettext gi-docgen gnomebase ptest-gnome upstream-version-is-even bash-completion gio-module-cache manpages gobject-introspection-data
+# GLib publishes bugfix/security-only micro releases on its stable
+# (even-minor) series.
+inherit gettext gi-docgen gnomebase ptest-gnome upstream-version-is-even bash-completion gio-module-cache manpages gobject-introspection-data upstream-stable-release-point
S = "${UNPACKDIR}/${GNOMEBN}-${PV}"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 32/79] dbus: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (30 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 31/79] glib-2.0: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 33/79] xz: " Yoann Congal
` (46 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
D-Bus's CONTRIBUTING.md documents even-minor stable branches, currently
dbus-1.16.x, that receive only cherry-picked bug fixes, so upgrades
within a major.minor are stable point upgrades per the OE-Core stable
release policy (ref-manual, "Stable Point Release Upgrades"). It also
states that odd-minor development branches such as 1.17.x are not
supported at all and receive no bug fixes, not even for security
vulnerabilities, so only the even-minor stable series should be tracked.
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://gitlab.freedesktop.org/dbus/dbus/-/blob/dbus-1.16.2/CONTRIBUTING.md#L65
Checked the only point release in the series so far for feature creep,
the 1.16.x series having just one non-.0 release to date:
1.16.2 (Feb 27 2025): two items -- one build-regression fix for
verbose-mode builds against libselinux >= 3.8, and a documentation
update. No API or behaviour changes.
Already tracked this way on the OE stable branches, counting only bumps
made since each branch forked from master: kirkstone 1.14.0 -> 1.14.8.
scarthgap has had zero point-release bumps since its fork and remains at
1.14.10; wrynose ships 1.16.2 as its initial version with no bump yet.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 63948049e50abeda630fb716ea0ba97e71b4f7cd)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-core/dbus/dbus_1.16.2.bb | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/meta/recipes-core/dbus/dbus_1.16.2.bb b/meta/recipes-core/dbus/dbus_1.16.2.bb
index 7425bd23642..1102a8660ee 100644
--- a/meta/recipes-core/dbus/dbus_1.16.2.bb
+++ b/meta/recipes-core/dbus/dbus_1.16.2.bb
@@ -5,6 +5,12 @@ SECTION = "base"
inherit meson pkgconfig gettext upstream-version-is-even ptest-gnome
+# D-Bus publishes bugfix/security-only micro releases on its stable
+# (even-minor) branches. Odd-minor development branches (e.g. 1.17.x) are
+# not supported at all and receive no bug fixes, not even for security
+# vulnerabilities, so only the even-minor stable series is tracked here.
+inherit upstream-stable-release-point
+
LICENSE = "AFL-2.1 | GPL-2.0-or-later"
LIC_FILES_CHKSUM = "file://COPYING;md5=eb0ffc69a965797a3d6686baa153ef05 \
file://dbus/dbus.h;beginline=6;endline=22;md5=df4251a6c6e15e6a9e3c77b2ac30065d \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 33/79] xz: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (31 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 32/79] dbus: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 34/79] git: " Yoann Congal
` (45 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
XZ Utils's README documents that an even minor (Y) is a stable series
where the revision (Z) "is incremented when bugs get fixed without adding
any new features". So upgrades within a major.minor are stable point
upgrades per the OE-Core stable release policy (ref-manual, "Stable Point
Release Upgrades").
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/tukaani-project/xz/blob/v5.8.3/README#L138
Checked the last two point releases for feature creep:
5.8.3 (Mar 31 2026): one CVE (CVE-2026-34743, a buffer overflow in
lzma_index_append), one invalid-memory-access fix, build portability
fixes for Windows ARM64EC and Hurd, and man page translations. No new
options or API.
5.8.2 (Dec 17 2025): build portability fixes for four toolchains, a
RHEL 9 kernel-bug workaround, and a resource-aware memory-limit default
tweak that is a bugfix rather than a new feature. No new options or
API.
Already tracked this way on the OE stable branches, counting only bumps
made since each branch forked from master: kirkstone picked up 5.2.6 and
scarthgap 5.4.7, one bump each.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Adapted for wrynose: applied to xz_5.8.2.bb (upstream: xz_5.8.3.bb).
(cherry picked from commit e336ba1ed32bc924dab329afe1d687e0382f1c87)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/xz/xz_5.8.2.bb | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/meta/recipes-extended/xz/xz_5.8.2.bb b/meta/recipes-extended/xz/xz_5.8.2.bb
index 15eaa7a52f8..5e7ad1fc704 100644
--- a/meta/recipes-extended/xz/xz_5.8.2.bb
+++ b/meta/recipes-extended/xz/xz_5.8.2.bb
@@ -33,6 +33,10 @@ SRC_URI[sha256sum] = "ce09c50a5962786b83e5da389c90dd2c15ecd0980a258dd01f70f9e7ce
UPSTREAM_CHECK_REGEX = "releases/tag/v(?P<pver>\d+(\.\d+)+)"
UPSTREAM_CHECK_URI = "https://github.com/tukaani-project/xz/releases/"
+# XZ Utils publishes bugfix/security-only micro releases on its stable
+# (even-minor) branches.
+inherit upstream-stable-release-point
+
CACHED_CONFIGUREVARS += "gl_cv_posix_shell=/bin/sh"
inherit autotools gettext ptest
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 34/79] git: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (32 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 33/79] xz: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 35/79] perl: " Yoann Congal
` (44 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
Git's maintainer documentation defines the version scheme explicitly:
vX.Y.0 are feature releases carrying bugfixes and enhancements in any
area, while vX.Y.Z (Z>0) maintenance releases "contain only bugfixes for
the corresponding vX.Y.0 feature release and earlier maintenance
releases". So upgrades within a major.minor are stable point upgrades per
the OE-Core stable release policy (ref-manual, "Stable Point Release
Upgrades").
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/git/git/blob/v2.55.0/Documentation/howto/maintain-git.adoc#L47
Checked recent maintenance releases for feature creep:
2.44.4 (May 28 2025): CVE fixes only, seven of them, merged up from the
fixes that appeared in v2.43.7. The release notes contain nothing else.
2.35.7 (Feb 06 2023): four fixes -- two libcurl portability fixes, and
two symlink-escape fixes in apply and clone back-merged from older
maintenance lines.
No 2.55.x point release exists yet, 2.55.0 being the current tip, so this
relies on the documented policy plus the historical pattern above rather
than a same-series point release. The ref-manual admits that basis: a
recipe may qualify on clear historical evidence that a class of bump is
bugfix-only (ref-manual, "Criteria for Qualifying Upstreams").
Already tracked this way on the OE stable branches, counting only bumps
made since each branch forked from master: kirkstone 2.35.2 -> 2.35.7,
five point bumps, and scarthgap 2.44.0 -> 2.44.4, three point bumps.
wrynose ships 2.53.0 as its initial version with no bump yet.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Adapted for wrynose: applied to git_2.53.0.bb (upstream: git_2.55.0.bb)
(cherry picked from commit 4300d9a707ee6ae2012ee03b4f4efae38521863c)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/git/git_2.53.0.bb | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/meta/recipes-devtools/git/git_2.53.0.bb b/meta/recipes-devtools/git/git_2.53.0.bb
index 8d71905f419..5244891113c 100644
--- a/meta/recipes-devtools/git/git_2.53.0.bb
+++ b/meta/recipes-devtools/git/git_2.53.0.bb
@@ -48,6 +48,10 @@ EXTRA_OECONF:append:class-native = " --with-gitconfig=/etc/gitconfig "
# Needs brokensep as this doesn't use automake
inherit autotools-brokensep perlnative bash-completion manpages
+# Git's maintainer docs define vX.Y.Z (Z>0) maintenance releases as
+# bugfix-only, scoped to the corresponding vX.Y.0 feature release.
+inherit upstream-stable-release-point
+
EXTRA_OEMAKE = "NO_PYTHON=1 CFLAGS='${CFLAGS}' LDFLAGS='${LDFLAGS}'"
EXTRA_OEMAKE += "'PERL_PATH=/usr/bin/env perl'"
EXTRA_OEMAKE += "COMPUTE_HEADER_DEPENDENCIES=no"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 35/79] perl: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (33 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 34/79] git: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 36/79] libxml2: " Yoann Congal
` (43 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
perlpolicy documents a strict maintenance-branch policy: new releases of
a maint branch may only contain security/CVE fixes, crashing bugs,
regressions, build and install blockers, portability fixes and factual
documentation corrections, and must not contain patches that "add or
remove features", "break binary compatibility", or "add new warnings or
errors or deprecate features". New dual-life module versions are
explicitly deferred to the next stable series. So upgrades within a
major.minor are stable point upgrades per the OE-Core stable release
policy (ref-manual, "Stable Point Release Upgrades"). Long-lived
per-even-minor maint branches back this up, maint-5.6 through maint-5.42,
with a documented back-porting vote process.
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/Perl/perl5/blob/v5.42.2/pod/perlpolicy.pod#L259
Checked the last two point releases for feature creep. perldelta makes
this easy to see, as maint releases carry no "Core Enhancements" section
at all:
5.42.2 (Mar 29 2026): one CVE in a vendored dependency, CVE-2026-4176
in Compress::Raw::Zlib, plus module version bumps. States "There are no
changes intentionally incompatible with 5.42.1".
5.42.1 (Mar 08 2026): four fixes -- a Configure fix so POSIX locale
values can be passed in for cross-compilation, an AIX thread-safe
locale workaround, a Win32 build fix, and module version bumps. States
"There are no changes intentionally incompatible with Perl 5.42.0".
5.42.0 (Jul 02 2025) is the series-opening release, not a point
release: it adds seven language-level features, confirming X.Y.0 bumps
are feature bumps that must stay outside the regex.
Cross-checked the previous series the same way: 5.40.1, 5.40.2 and 5.40.3
all show the same profile, with security, module, documentation, test and
bug-fix sections only and no Core Enhancements.
The policy forbidding binary-compatibility breaks in maint releases also
covers the ABI concern directly.
Already tracked this way on the OE stable branches, counting only bumps
made since each branch forked from master: kirkstone 5.34.1 -> 5.34.3 and
scarthgap 5.38.2 -> 5.38.4 are both in-series point bumps. wrynose is
still at 5.42.0 while master is at 5.42.2, so it is missing the
CVE-2026-4176 fix -- exactly the tracking gap --stable is meant to close.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Adapted for wrynose: applied to perl_5.42.0.bb (upstream: perl_5.44.0.bb).
(cherry picked from commit 73ae055e5a05078225226355f1545fc9e464e78d)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/perl/perl_5.42.0.bb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb
index 6f0092c1cc7..886eaaaa379 100644
--- a/meta/recipes-devtools/perl/perl_5.42.0.bb
+++ b/meta/recipes-devtools/perl/perl_5.42.0.bb
@@ -35,7 +35,7 @@ SRC_URI[perl.sha256sum] = "e093ef184d7f9a1b9797e2465296f55510adb6dab8842b0c3ed53
B = "${WORKDIR}/perl-${PV}-build"
-inherit upstream-version-is-even update-alternatives
+inherit upstream-version-is-even update-alternatives upstream-stable-release-point
DEPENDS += "perlcross-native bzip2 zlib virtual/crypt"
DEPENDS:append:class-native = " bzip2-replacement-native"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 36/79] libxml2: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (34 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 35/79] perl: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 37/79] python3: " Yoann Congal
` (42 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
libxml2 maintains per-minor stable branches (2.9 through 2.15) that take
only bug-fix micro releases, and releases from several of them in
parallel: 2.13.9 and 2.14.6 went out the same day, after 2.14.5 was
already out. So upgrades within a major.minor are stable point upgrades
per the OE-Core stable release policy (ref-manual, "Stable Point Release
Upgrades").
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://gitlab.gnome.org/GNOME/libxml2/-/tree/2.15
Checked the last three point releases. 2.15.3 (Apr 15 2026) is five
security fixes plus an "Improvements" section that is also entirely fixes,
and 2.15.1 (Oct 16 2025) is security, regression and build fixes. 2.15.2
(Mar 03 2026) is five CVE fixes plus one addition, a --xpath0 option
confined to the xmllint command-line tool.
A public-header diff across the three shows zero added, removed or changed
libxml2.so declarations, so the library API and ABI are unaffected by that
addition.
Already tracked this way on the OE stable branches, counting only bumps
since each branch forked: kirkstone picked up 2.9.14, scarthgap 2.12.5 ->
2.12.10.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Adapted for wrynose: applied to libxml2_2.15.2.bb (upstream: libxml2_2.15.3.bb).
(cherry picked from commit a9fd7975e991124b8f54c4c763917e705fb4213c)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-core/libxml/libxml2_2.15.4.bb | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/meta/recipes-core/libxml/libxml2_2.15.4.bb b/meta/recipes-core/libxml/libxml2_2.15.4.bb
index fc367892bfe..896b33f2677 100644
--- a/meta/recipes-core/libxml/libxml2_2.15.4.bb
+++ b/meta/recipes-core/libxml/libxml2_2.15.4.bb
@@ -30,6 +30,10 @@ BINCONFIG = "${bindir}/xml2-config"
inherit autotools pkgconfig binconfig-disabled ptest
+# libxml2 publishes bugfix/security-only micro releases on its per-minor
+# release branches.
+inherit upstream-stable-release-point
+
LDFLAGS:append:riscv64 = "${@bb.utils.contains('DISTRO_FEATURES', 'ld-is-lld ptest', ' -fuse-ld=bfd', '', d)}"
RDEPENDS:${PN}-ptest += "locale-base-en-us"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 37/79] python3: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (35 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 36/79] libxml2: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 38/79] openssl: " Yoann Congal
` (41 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
Python maintains each release series on a per-minor maintenance branch
that, once released, takes bug and security fixes only, and it releases
from several at once: 3.10.20, 3.11.15 and 3.12.13 all went out on
2026-03-03, after 3.14.3. So upgrades within a major.minor are stable
point upgrades per the OE-Core stable release policy (ref-manual, "Stable
Point Release Upgrades").
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://devguide.python.org/versions/
Checked the last three point releases by category, since these are
substantial bug-fix releases rather than security-only. 3.14.6 (Jun 10
2026) has 8 Security, 32 Library and 17 Core entries; 3.14.4 (Apr 07 2026)
has 5, 59 and 46. Every C API entry in both is a fix, so neither adds C
API. 3.14.5 (May 10 2026) is mostly fixes but does add RFC 9309 support to
urllib.robotparser -- one extra capability in one module, touching neither
the language, the C API nor the stable ABI.
Already tracked this way on the OE stable branches, counting only bumps
since each branch forked: kirkstone 3.10.4 -> 3.10.20, scarthgap 3.12.3 ->
3.12.13, wrynose 3.14.4 -> 3.14.6.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
(cherry picked from commit e49e237208a9a5074d7bbc65b748962f3ea0eb49)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3_3.14.7.bb | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/meta/recipes-devtools/python/python3_3.14.7.bb b/meta/recipes-devtools/python/python3_3.14.7.bb
index b798f1c3697..e73dc8d7728 100644
--- a/meta/recipes-devtools/python/python3_3.14.7.bb
+++ b/meta/recipes-devtools/python/python3_3.14.7.bb
@@ -45,6 +45,10 @@ SRC_URI[sha256sum] = "3b48dac8fb59f62eaa67ac83c1eb12bda1b7a08406dd286e252c11a66b
# exclude pre-releases for both python 2.x and 3.x
UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>\d+(\.\d+)+).tar"
+# Python publishes bugfix/security-only releases on its per-minor
+# maintenance branches.
+inherit upstream-stable-release-point
+
CVE_PRODUCT = "python:python python_software_foundation:python cpython"
PYTHON_MAJMIN = "3.14"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 38/79] openssl: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (36 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 37/79] python3: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 39/79] binutils: " Yoann Congal
` (40 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
OpenSSL's release strategy states that patch releases contain only bug and
security fixes, with no new features and no API or ABI breaking changes.
It maintains several series at once: 3.0.21, 3.4.6, 3.5.7 and 3.6.3 were
all released on 2026-06-09, with 4.0.0 already out. So upgrades within a
major.minor are stable point upgrades per the OE-Core stable release
policy (ref-manual, "Stable Point Release Upgrades").
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://openssl-library.org/policies/releasestrat/
Checked the last three point releases. Each is labelled "a security patch
release" in its own NEWS.md header, and every entry is a CVE fix, the item
count matching the unique CVE count exactly: 15 CVEs in 3.5.7 (Jun 09
2026), 7 in 3.5.6 (Apr 07 2026), 12 in 3.5.5 (Jan 27 2026).
When a series reaches EOL the regex must be moved to the next maintained
series by hand, as that is a feature-level change.
One limit is worth stating, from this recipe's own history: 3.2.4 -> 3.2.5
was refused on scarthgap in July 2025 for intermittent ptest failures in a
dependent recipe, bisected to an upstream commit and reported upstream,
and the branch went to 3.2.6 instead. A fixes-only release can still fail
to integrate, so proposing an upgrade is not the same as it passing.
Already tracked this way on the OE stable branches, counting only bumps
since each branch forked: kirkstone 3.0.2 -> 3.0.19 on the 3.0 LTS series;
scarthgap 3.2.1 -> 3.2.6 then, at EOL, 3.5.5 -> 3.5.7; wrynose picked up
3.5.7.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
(cherry picked from commit 75f78c58cf9e4b385ddf4f09668b7f1a49117d97)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-connectivity/openssl/openssl_3.5.8.bb | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.8.bb b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb
index cc148f07c7d..d8cae41291a 100644
--- a/meta/recipes-connectivity/openssl/openssl_3.5.8.bb
+++ b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb
@@ -24,6 +24,11 @@ SRC_URI[sha256sum] = "a8f84a39918ec6415ce765d9b429d313ba97b8143169c172e734b95144
inherit lib_package multilib_header multilib_script ptest perlnative manpages
MULTILIB_SCRIPTS = "${PN}-bin:${bindir}/c_rehash"
+# OpenSSL publishes bugfix/security-only releases on its per-minor branches.
+# When the tracked series reaches EOL, bump the regex manually to the next
+# maintained series.
+inherit upstream-stable-release-point
+
PACKAGECONFIG ?= ""
PACKAGECONFIG:class-native = ""
PACKAGECONFIG:class-nativesdk = ""
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 39/79] binutils: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (37 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 38/79] openssl: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 40/79] libgcrypt: " Yoann Congal
` (39 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
binutils cuts a per-X.Y stable branch, binutils-2_46-branch for the
current series, that takes only bugfixes and backported CVE fixes, and
tags X.Y.Z (Z>0) releases from it. Superseded branches stay alive: one x86
MODRM fix landed on the 2.40, 2.42 and 2.43 branches on the same day in
May 2025. So upgrades within a major.minor are stable point upgrades per
the OE-Core stable release policy (ref-manual, "Stable Point Release
Upgrades"). This is not spelled out in a policy document, so qualification
rests on the branch structure and the release contents below.
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://sourceware.org/git/?p=binutils-gdb.git;a=shortlog;h=refs/heads/binutils-2_46-branch
Checked the last two point releases. 2.46.1 (Jun 08 2026) is 137 commits,
mostly automatic version-string date bumps, with six substantive changes,
all fixes: gprof testsuite, build warnings, an sframe encoder/decoder
call-site fix, a DOS-filesystem fix and two linker fixes. 2.45.1 (Nov 10
2025) is aarch64/gas fixes to incorrectly restricted instruction
encodings, linker metadata fixes adding GLIBC_ABI_*_TLS version
dependencies to match glibc's own ABI tags, and libctf, strip and warning
fixes. Neither adds options or instruction support.
Already tracked this way on the OE stable branches, counting only bumps
since each branch forked: kirkstone has five or more "binutils: stable
2.38 branch update(s)" commits staying within 2.38.x, scarthgap the same
for 2.42.x, and wrynose has already taken 2.46.1.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
(cherry picked from commit e61767b8d9486c1a13f505563919654af5955a23)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/binutils/binutils.inc | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/meta/recipes-devtools/binutils/binutils.inc b/meta/recipes-devtools/binutils/binutils.inc
index b3d0728e4b2..29c05b1a279 100644
--- a/meta/recipes-devtools/binutils/binutils.inc
+++ b/meta/recipes-devtools/binutils/binutils.inc
@@ -15,6 +15,11 @@ DEPENDS = "flex-native bison-native zlib-native gnu-config-native autoconf-nativ
inherit autotools gettext multilib_header pkgconfig texinfo
+# binutils maintains a stable branch per X.Y release (e.g. binutils-2_46-branch)
+# that only takes bugfixes and backported CVE fixes; X.Y.Z (Z>0) releases are
+# cut from that branch.
+inherit upstream-stable-release-point
+
FILES:${PN} = " \
${bindir}/${TARGET_PREFIX}* \
${libdir}/lib*.so.* \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 40/79] libgcrypt: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (38 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 39/79] binutils: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 41/79] sqlite3: " Yoann Congal
` (38 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
libgcrypt keeps a long-lived maintenance branch per minor version,
LIBGCRYPT-1.12-BRANCH matching the current PV with equivalents back to
1.2, and releases from several in parallel: in one week of April 2026 it
released into four of them, 1.12.2 and 1.8.13 on the 15th, 1.11.3 and
1.10.4 on the 21st. So upgrades within a major.minor are stable point
upgrades per the OE-Core stable release policy (ref-manual, "Stable Point
Release Upgrades").
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/gpg/libgcrypt/tree/LIBGCRYPT-1.12-BRANCH
NEWS separates "Bug fixes" from "New and extended interfaces", and neither
point release in the current series has the latter section at all: 1.12.2
(Apr 15 2026) is four fixes, including an ECDH buffer overwrite and a
missing Dilithium bounds check, and 1.12.1 (Feb 20 2026) four build or
arithmetic regressions. 1.12.0 (Jan 29 2026) opens the series and does add
features, confirming X.Y.0 bumps must stay outside the regex.
The libtool version-info in each NEWS heading is upstream's own ABI
record, and across the current series only the revision moves. One
deviation is worth disclosing from the previous series: 1.11.2 adds a
single enum constant, GCRY_KEM_RAW_P256R1, with current and age
incremented together so it stays backward compatible. Point releases here
are fixes-focused rather than absolutely fixes-only, with the deviation
bounded to additive constants.
Already tracked this way on the OE stable branches, counting only bumps
since each branch forked: scarthgap took 1.10.3 -> 1.10.4, which needed a
build fix backported alongside it because 1.10.4 broke building with -O2
in the sysroot path. kirkstone has taken no in-series bump and stays at
1.9.4.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Adapted for wrynose: applied to libgcrypt_1.12.1.bb (upstream: libgcrypt_1.12.2.bb).
(cherry picked from commit 97caf8a110281becde5d888338712d71627cbf98)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-support/libgcrypt/libgcrypt_1.12.1.bb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/recipes-support/libgcrypt/libgcrypt_1.12.1.bb b/meta/recipes-support/libgcrypt/libgcrypt_1.12.1.bb
index d7f8563ae6e..d7b3e182cd2 100644
--- a/meta/recipes-support/libgcrypt/libgcrypt_1.12.1.bb
+++ b/meta/recipes-support/libgcrypt/libgcrypt_1.12.1.bb
@@ -32,7 +32,7 @@ SRC_URI[sha256sum] = "7df5c08d952ba33f9b6bdabdb06a61a78b2cf62d2122c2d1d03a91a798
BINCONFIG = "${bindir}/libgcrypt-config"
-inherit autotools texinfo binconfig-disabled pkgconfig ptest
+inherit autotools texinfo binconfig-disabled pkgconfig ptest upstream-stable-release-point
require recipes-support/gnupg/drop-unknown-suffix.inc
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 41/79] sqlite3: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (39 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 40/79] libgcrypt: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 42/79] lttng-tools: " Yoann Congal
` (37 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
SQLite cuts a per-minor maintenance branch for each release series,
branch-3.53 matching the current PV alongside branch-3.52, -3.51 and
-3.50, and tags patch releases off it. Superseded branches keep receiving
them: 3.44.5 and 3.42.1 were released in mid-2025, long after 3.50 was
current. So upgrades within a major.minor are stable point upgrades per
the OE-Core stable release policy (ref-manual, "Stable Point Release
Upgrades").
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/sqlite/sqlite/tree/branch-3.53
Checked the whole current series. 3.53.1 (May 05 2026) through 3.53.4 (Jul
24 2026) are almost entirely memory-safety and corruption-handling fixes:
five out-of-bounds reads, two buffer overreads or overwrites, two integer
overflows, hot-journal rollback with a zeroed super-journal record, safer
double-to-int64 conversion, and mutex acquisition added to a batch of
sqlite3_* entry points. 3.53.0 (Apr 09 2026) opens the series and does add
API surface, confirming X.Y.0 bumps must stay outside the regex.
Two additive exceptions in 3.53.4, neither touching the core library ABI:
the SQLITE_SHELL_EDITION compile-time option for the CLI, and
sqlite3_intck_register() in the incremental integrity-check extension.
Already tracked this way on the OE stable branches, counting only bumps
since each branch forked: kirkstone 3.38.2 -> 3.38.3 -> 3.38.5 and
scarthgap 3.45.1 -> 3.45.3. wrynose is at 3.51.3 with no in-series bump
yet.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
(cherry picked from commit 22cd1dfc82049e47be5e73057c2f12cda036f352)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-support/sqlite/sqlite3.inc | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/recipes-support/sqlite/sqlite3.inc b/meta/recipes-support/sqlite/sqlite3.inc
index 94dbc38ec5e..8791749dc85 100644
--- a/meta/recipes-support/sqlite/sqlite3.inc
+++ b/meta/recipes-support/sqlite/sqlite3.inc
@@ -21,7 +21,7 @@ UPSTREAM_CHECK_REGEX = "releaselog/(?P<pver>(\d+[\.\-_]*)+)\.html"
CVE_PRODUCT = "sqlite"
-inherit pkgconfig siteinfo
+inherit pkgconfig siteinfo upstream-stable-release-point
# enable those which are enabled by default in configure
PACKAGECONFIG ?= "fts4 fts5 rtree dyn_ext"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 42/79] lttng-tools: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (40 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 41/79] sqlite3: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 43/79] util-linux: " Yoann Congal
` (36 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
lttng-tools maintains a branch per minor series (stable-2.11 through
stable-2.16) and tags point releases from it, releasing from more than one
at a time: 2.14.2 and 2.15.1 went out the same day. So upgrades within a
major.minor are stable point upgrades per the OE-Core stable release
policy (ref-manual, "Stable Point Release Upgrades"). There is no written
policy document, so qualification rests on the branch structure and the
release contents below.
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/lttng/lttng-tools/blob/v2.15.1/ChangeLog
https://github.com/lttng/lttng-tools/tree/stable-2.15
Upstream keeps a ChangeLog with a per-release entry list, and all 48
entries for 2.15.1 (Jun 05 2026, against 2.15.0 in February) are fixes,
tests, documentation or refactors. Seven address machine interface output
alone; the rest cover a consumerd lockfile fd leak across fork+exec, a
missing default kernel probe entry, an uninitialised read in uri_compare,
a musl compatibility fix, popt error handling, test fixes, and one
refactor preparing the CPU-mask escaping fix.
Already tracked this way on the OE stable branches, counting only bumps
since each branch forked: kirkstone took 2.13.4 -> 2.13.8 and 2.13.8 ->
2.13.9, scarthgap 2.13.11 -> 2.13.13. wrynose has taken none and sits at
2.14.1.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Adapted for wrynose: applied to lttng-tools_2.14.1.bb (upstream: lttng-tools_2.15.1.bb).
(cherry picked from commit 40f22582ff6989f9275808bfda229a8ec78504e4)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: lttng-tools has a written stable policy:
https://github.com/lttng/lttng-tools/tree/stable-2.15#supported-versions
|The LTTng project supports the last two released stable versions
|(e.g. stable-2.13 and stable-2.12).
|
|Fixes are backported from the master branch to the last stable version unless
|those fixes would break the ABI or API. Those fixes may be backported to the
|second-last stable version, depending on complexity and ABI/API compatibility.
|
|Security fixes are backported from the master branch to both of the last stable
|version and the second-last stable version.
|
|New features are integrated into the master branch and not backported to the
|last stable branch.
]
---
meta/recipes-kernel/lttng/lttng-tools_2.14.1.bb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/recipes-kernel/lttng/lttng-tools_2.14.1.bb b/meta/recipes-kernel/lttng/lttng-tools_2.14.1.bb
index 3a3f2cff2c6..3df9ed1c00c 100644
--- a/meta/recipes-kernel/lttng/lttng-tools_2.14.1.bb
+++ b/meta/recipes-kernel/lttng/lttng-tools_2.14.1.bb
@@ -54,7 +54,7 @@ SRC_URI = "https://lttng.org/files/lttng-tools/lttng-tools-${PV}.tar.bz2 \
SRC_URI[sha256sum] = "0e68eb27923621c4bc127cfce40422d28cf7e473fedf6229ae6c32ba5c5b7c6d"
-inherit autotools ptest pkgconfig useradd python3-dir manpages systemd
+inherit autotools ptest pkgconfig useradd python3-dir manpages systemd upstream-stable-release-point
CACHED_CONFIGUREVARS = "PGREP=/usr/bin/pgrep"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 43/79] util-linux: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (41 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 42/79] lttng-tools: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 44/79] lttng-ust: " Yoann Congal
` (35 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
util-linux's README ("Stable Branches") documents stable/v<major>.<minor>
branches whose maintenance releases are bug fixes only, so upgrades
within a major.minor are stable point upgrades per the OE-Core stable
release policy (ref-manual, "Stable Point Release Upgrades").
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/util-linux/util-linux/blob/v2.42.2/README#L95
Checked the last point release for feature creep:
2.42.2 (Jun 16 2026), against 2.42.1 (May 18 2026): 32 commits, all
fixes or hardening -- memory safety (a libblkid use-after-free, two
buffer overflows, a libfdisk GPT fix), privilege tightening
(X-mount.subdir restricted for non-root), diagnostics (fanotify queue
overflow detection) and documentation. No new options or behaviour.
These releases are not picked up on the OE stable branches: util-linux has
had zero point-release bumps on kirkstone, scarthgap or wrynose since each
branch forked from master, leaving them at 2.37.4, 2.39.3 and 2.41.3
respectively. This addresses that gap going forward.
Scarthgap already has v2.39.3, and the 2.39.x stable branch history (mount
API regression fix in 2.39.1, new CPU model support, and libblkid’s bcachefs
handling) demonstrates that util-linux exercises good judgement in managing
stable branches, so we can safely track their stable series there as well.
For the avoidance of doubt it is not a development-series effect either:
util-linux has no development/stable version split, and pre-release work
goes to -rc tags.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit d51c6e87a10c7c75a692ca86b71af9a818026ecb)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-core/util-linux/util-linux.inc | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc
index 09916594b0a..be49160eac9 100644
--- a/meta/recipes-core/util-linux/util-linux.inc
+++ b/meta/recipes-core/util-linux/util-linux.inc
@@ -28,3 +28,7 @@ SRC_URI[sha256sum] = "f586e35d320ff537aab3ffeca37e9ecd482ccbe013590db4429a414d8a
CVE_PRODUCT = "util-linux"
CVE_STATUS[CVE-2026-13595] = "cpe-stable-backport: Fixed from version >=2.41.5"
+
+# util-linux publishes bugfix/security-only point releases on its
+# stable/v<major.minor> branches.
+inherit upstream-stable-release-point
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 44/79] lttng-ust: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (42 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 43/79] util-linux: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 45/79] babeltrace2: " Yoann Congal
` (34 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
lttng-ust maintains a branch per minor series (stable-2.13 through
stable-2.16) and releases from several at once: 2.14.2 and 2.15.1 went out
the same day in May 2026, and three series together in February, 2.13.10,
2.14.1 and 2.15.0. So upgrades within a major.minor are stable point
upgrades per the OE-Core stable release policy (ref-manual, "Stable Point
Release Upgrades"). There is no written policy document, so qualification
rests on that branch structure and the release contents below.
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/lttng/lttng-ust/tree/stable-2.15
Upstream keeps a ChangeLog with a per-release entry list, and every entry
for the one point release in the current series is labelled a fix. 2.15.1
(May 22 2026) covers a negative error code on incorrect message size, a
shmp() return value checked before dereference, an underflow warning in
zero_file, uninitialised LTTNG_UST_LFILE and sigevent structs, close_range
inefficiency and excessive fd-tracker memory use, and a NULL check in
ustctl. The one non-fix entry changes a likely to unlikely branch hint.
Only one point release exists in the 2.15 series so far, so this also
rests on the 2.13 series' record, which ran to ten.
Already tracked this way on the OE stable branches, counting only bumps
since each branch forked: kirkstone took 2.13.5 -> 2.13.6 and scarthgap
2.13.7 -> 2.13.8 -> 2.13.10. wrynose has taken none and sits at 2.14.0.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Adapted for wrynose: applied to lttng-ust_2.14.0.bb (upstream: lttng-ust_2.15.1.bb).
(cherry picked from commit a5dcaef20fc91539efa08b47607c4c91f4f49849)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: lttng-ust stable policy:
https://github.com/lttng/lttng-tools/blob/stable-2.15/README.adoc#supported-versions:
|Supported versions
|------------------
|
|The LTTng project supports the last two released stable versions
|(e.g. stable-2.13 and stable-2.12).
|
|Fixes are backported from the master branch to the last stable version
|unless those fixes would break the ABI or API. Those fixes may be backported
|to the second-last stable version, depending on complexity and ABI/API
|compatibility.
|
|Security fixes are backported from the master branch to both of the last stable
|version and the the second-last stable version.
|
|New features are integrated into the master branch and not backported to the
|last stable branch.
]
---
meta/recipes-kernel/lttng/lttng-ust_2.14.0.bb | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/meta/recipes-kernel/lttng/lttng-ust_2.14.0.bb b/meta/recipes-kernel/lttng/lttng-ust_2.14.0.bb
index 1a15c5b4201..4285a445d67 100644
--- a/meta/recipes-kernel/lttng/lttng-ust_2.14.0.bb
+++ b/meta/recipes-kernel/lttng/lttng-ust_2.14.0.bb
@@ -11,7 +11,9 @@ PYTHON_OPTION = "am_cv_python_pyexecdir='${PYTHON_SITEPACKAGES_DIR}' \
PYTHON_INCLUDE='-I${STAGING_INCDIR}/python${PYTHON_BASEVERSION}${PYTHON_ABI}' \
"
-inherit autotools lib_package manpages python3native pkgconfig
+# lttng-ust publishes bugfix/security-only releases on its per-minor
+# stable-X.Y branches, the same upstream and release model as lttng-tools.
+inherit autotools lib_package manpages python3native pkgconfig upstream-stable-release-point
include lttng-platforms.inc
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 45/79] babeltrace2: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (43 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 44/79] lttng-ust: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 46/79] lttng-modules: " Yoann Congal
` (33 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
babeltrace2 maintains a branch per minor series (stable-2.0, stable-2.1)
and keeps the older one alive: 2.0.7 and 2.1.2 were released the same day
in July 2025, with 2.1.1 already out since April. So upgrades within a
major.minor are stable point upgrades per the OE-Core stable release
policy (ref-manual, "Stable Point Release Upgrades"). There is no written
policy document, so qualification rests on that branch structure and the
release contents below.
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/efficios/babeltrace/tree/stable-2.1
Upstream keeps a ChangeLog with a per-release entry list. Both point
releases in the current series are fixes, tests and documentation: 2.1.2
(Jul 22 2025) is 13 commits, and 2.1.1 (Apr 14 2025) 10.
Already tracked this way on the OE stable branches, counting only bumps
since each branch forked: kirkstone took 2.0.4 -> 2.0.5 and scarthgap
2.0.5 -> 2.0.6. wrynose has taken none and sits at 2.1.2.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 3d742fa47d795b6b013d5ca3d78f0dd601432832)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-kernel/lttng/babeltrace2_2.1.2.bb | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/meta/recipes-kernel/lttng/babeltrace2_2.1.2.bb b/meta/recipes-kernel/lttng/babeltrace2_2.1.2.bb
index b0cd6efde18..5b9c02b0c21 100644
--- a/meta/recipes-kernel/lttng/babeltrace2_2.1.2.bb
+++ b/meta/recipes-kernel/lttng/babeltrace2_2.1.2.bb
@@ -19,7 +19,9 @@ SRC_URI = "git://git.efficios.com/babeltrace.git;branch=stable-2.1;protocol=http
SRCREV = "d0e946a71faf5f0c2d7f1fb5b92a369983e9cf10"
UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>2(\.\d+)+)$"
-inherit autotools pkgconfig ptest setuptools3-base
+# babeltrace2 publishes bugfix/security-only releases on its per-minor
+# stable-X.Y branches.
+inherit autotools pkgconfig ptest setuptools3-base upstream-stable-release-point
EXTRA_OECONF = "--disable-debug-info --disable-Werror --enable-python-plugins --enable-python-bindings"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 46/79] lttng-modules: inherit upstream-stable-release-point
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (44 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 45/79] babeltrace2: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 47/79] libslirp: fix upstream version check Yoann Congal
` (32 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
The LTTng project documents its stable-branch policy in README.md,
"Supported versions" at L171: fixes are backported to the last stable
version unless they would break the ABI or API, and security fixes to the
last two. So upgrades within a major.minor are stable point upgrades per
the OE-Core stable release policy (ref-manual, "Stable Point Release
Upgrades").
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/lttng/lttng-modules/blob/v2.15.2/README.md#supported-versions
https://github.com/lttng/lttng-modules/tree/stable-2.15
This recipe's policy differs from the rest of the project in one respect
worth stating. Where lttng-ust and lttng-tools do not backport new
features at all, L185 says kernel-version enablement is backported to the
last stable version. That is the only non-fix content a point release
carries, and for a kernel tracer it keeps existing probes working against
newer kernels rather than adding anything a user can call: no new options,
no new API, no changed defaults. Upstream labels these entries "fix:"
alongside the rest.
Six branches are maintained in parallel, stable-2.11 through stable-2.16,
and released from together: 2.14.6 and 2.15.2 the same day in June 2026,
2.14.5 and 2.15.1 in April, seven such days in the last two years.
The ChangeLog entries for the current series are fixes throughout. 2.15.2
(Jun 19 2026) is 13 entries: a leaked file and fd on channel create error,
plus twelve probe adjustments tracking kernel changes to ext4, btrfs, vfs,
vmscan and hrtimer tracepoints. 2.15.1 (Apr 24 2026) is three, covering
kallsyms on powerpc64 with ABI V1, a snd_soc_dapm_context move and a btrfs
probe range.
This recipe must share its minor version with lttng-ust and lttng-tools:
lttng-tools README.adoc L123 states it supports the kernel and user space
tracers "sharing the same _minor_ version", and that cross-version
combinations are untested. Pinning the regex to the minor is what keeps
that guarantee, permitting 2.15.x -> 2.15.y and excluding the 2.15 -> 2.16
bump that would need the three coordinated. Within a series they have
never moved together on any branch: taking modules, tools and ust in turn,
kirkstone ships 2.13.14, 2.13.9 and 2.13.6; scarthgap 2.13.12, 2.13.13 and
2.13.10; wrynose 2.14.4, 2.14.1 and 2.14.0. The minor agrees in every row
and the patch in none, and scarthgap has lttng-tools ahead of this recipe
rather than behind. There is no build dependency between them either.
Already tracked this way on the OE stable branches, and more thoroughly
than most: counting only bumps since each branch forked, kirkstone took
2.13.4 -> 2.13.5 -> 2.13.7 -> 2.13.8 -> 2.13.9 -> 2.13.14, scarthgap
2.13.9 -> 2.13.10 -> 2.13.11 -> 2.13.12, and wrynose 2.14.0 through
2.14.4. Each also carries local "fix build for kernel N" patches between
those bumps, which is the burden that staying current within a series
reduces.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Adapted for wrynose: applied to lttng-modules_2.14.4.bb (upstream: lttng-modules_2.15.2.bb).
(cherry picked from commit d4666244a51c7fb8fa7e66c11d91692197c89ce7)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-kernel/lttng/lttng-modules_2.14.4.bb | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/meta/recipes-kernel/lttng/lttng-modules_2.14.4.bb b/meta/recipes-kernel/lttng/lttng-modules_2.14.4.bb
index b2c697d365d..d0983f58cbe 100644
--- a/meta/recipes-kernel/lttng/lttng-modules_2.14.4.bb
+++ b/meta/recipes-kernel/lttng/lttng-modules_2.14.4.bb
@@ -7,6 +7,12 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=018e002dbdda3306682e394ddd65fa32"
inherit module
+# lttng-modules publishes bugfix/security-only releases on its per-minor
+# stable-X.Y branches. Point releases also carry kernel-version enablement,
+# which keeps existing probes working against newer kernels rather than adding
+# user-visible functionality.
+inherit upstream-stable-release-point
+
include lttng-platforms.inc
SRC_URI = "https://lttng.org/files/${BPN}/${BPN}-${PV}.tar.bz2 \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 47/79] libslirp: fix upstream version check
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (45 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 46/79] lttng-modules: " Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 48/79] libslirp: upgrade 4.9.1 -> 4.9.3 Yoann Congal
` (31 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Alexander Kanavin <alex@linutronix.de>
The regex excludes bogus old yyyymmdd tags which sort higher than real versions.
Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 2a60e5db4460cd8ec99b43d8f2ff733ba509c373)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-connectivity/slirp/libslirp_4.9.1.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb b/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb
index 9f7005d7098..50577fd4ae2 100644
--- a/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb
+++ b/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb
@@ -6,6 +6,7 @@ LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=bca0186b14e6b05e338e729f106db727"
SRC_URI = "git://gitlab.freedesktop.org/slirp/libslirp.git;protocol=https;branch=master"
SRCREV = "9c744e1e52aa0d9646ed91d789d588696292c21e"
+UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>\d+(\.\d+)+)"
DEPENDS = "glib-2.0"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 48/79] libslirp: upgrade 4.9.1 -> 4.9.3
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (46 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 47/79] libslirp: fix upstream version check Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 49/79] libslirp: add tag in SRC_URI Yoann Congal
` (30 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Alexander Kanavin <alex@linutronix.de>
License-Update: license moved to a separate file
https://gitlab.com/qemu-project/libslirp/-/commit/d6cfac6d060d57c0e38a9c61157eaf6962b6c257
Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 16f511425c537239e487b73998f9d8133a8ca2c4)
Full release notes:
* https://gitlab.freedesktop.org/slirp/libslirp/-/blob/v4.9.3/CHANGELOG.md?ref_type=tags
It also shows one "change":
* bootp: allow https for UEFI HTTP boot
It however does not change ABI and can also be interpreted as security
feature (allowing https), thus should be allowed for LTS backport.
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../slirp/{libslirp_4.9.1.bb => libslirp_4.9.3.bb} | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
rename meta/recipes-connectivity/slirp/{libslirp_4.9.1.bb => libslirp_4.9.3.bb} (70%)
diff --git a/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb b/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb
similarity index 70%
rename from meta/recipes-connectivity/slirp/libslirp_4.9.1.bb
rename to meta/recipes-connectivity/slirp/libslirp_4.9.3.bb
index 50577fd4ae2..734e59a59b1 100644
--- a/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb
+++ b/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb
@@ -2,10 +2,11 @@ SUMMARY = "A general purpose TCP-IP emulator"
DESCRIPTION = "A general purpose TCP-IP emulator used by virtual machine hypervisors to provide virtual networking services."
HOMEPAGE = "https://gitlab.freedesktop.org/slirp/libslirp"
LICENSE = "BSD-3-Clause & MIT"
-LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=bca0186b14e6b05e338e729f106db727"
+LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=f95a9bf4a7e411164fe843697ccda59e \
+ file://LICENSE;md5=cfea6044642fd63b90ce9d79f5db64d9"
SRC_URI = "git://gitlab.freedesktop.org/slirp/libslirp.git;protocol=https;branch=master"
-SRCREV = "9c744e1e52aa0d9646ed91d789d588696292c21e"
+SRCREV = "dd76415fce457e319d665eb8210d05c5731360ba"
UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>\d+(\.\d+)+)"
DEPENDS = "glib-2.0"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 49/79] libslirp: add tag in SRC_URI
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (47 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 48/79] libslirp: upgrade 4.9.1 -> 4.9.3 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 50/79] expat: upgrade 2.7.5 -> 2.8.3 Yoann Congal
` (29 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
This is partial cherry-pick for single recipe:
* 00864cf5bcb6d85ec73d338c3e17e263512409a4
It will allow future cherry-picks from mastear and also uses single
filename in downloads mirror between master and wrynose (tag is added to
filename).
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-connectivity/slirp/libslirp_4.9.3.bb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb b/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb
index 734e59a59b1..1b45fd32479 100644
--- a/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb
+++ b/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb
@@ -5,7 +5,7 @@ LICENSE = "BSD-3-Clause & MIT"
LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=f95a9bf4a7e411164fe843697ccda59e \
file://LICENSE;md5=cfea6044642fd63b90ce9d79f5db64d9"
-SRC_URI = "git://gitlab.freedesktop.org/slirp/libslirp.git;protocol=https;branch=master"
+SRC_URI = "git://gitlab.freedesktop.org/slirp/libslirp.git;protocol=https;branch=master;tag=v${PV}"
SRCREV = "dd76415fce457e319d665eb8210d05c5731360ba"
UPSTREAM_CHECK_GITTAGREGEX = "v(?P<pver>\d+(\.\d+)+)"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 50/79] expat: upgrade 2.7.5 -> 2.8.3
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (48 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 49/79] libslirp: add tag in SRC_URI Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 51/79] curl: patch CVE-2026-7009 Yoann Congal
` (28 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Upgrade to 2.8.3, dropping 26 backported CVE patches (12 CVEs). This
is an exception to the usual stable upgrade policy as we are carrying
a large number of patches that are all included upstream in 2.8.3.
ABI compatibility verified with abidiff between 2.7.5 and 2.8.3 — no
ABI break and no SONAME major bump. Changelog reviewed — no feature
removals or backward-incompatible changes; only opt-in additions
disabled by default.
bitbake world -k built with oe-core + meta-openembedded layers, no
expat-related failures. All direct expat dependents built successfully:
apr-util, avahi, cmake, createrepo-c, dbus, dbus-broker, dbus-glib,
exiv2, fontconfig, gdb, git, graphviz, lftp, libcomps, libdbus-c++,
libsolv, libwmf, libxml-parser-perl, log4c, matchbox-keyboard,
matchbox-wm, mesa, neon, poco, python3, python3-dbus, sdbus-c++,
sdbus-c++-tools, serf, subversion, unbound, wayland, wbxml2, wireshark
Ptests passed on qemux86-64 for expat and its runtime consumers:
core-image-ptest-expat: OK
core-image-ptest-python3: OK
core-image-ptest-libxml-parser-perl: OK
Additionally includes fixes for (not previously backported):
CVE-2026-50219 CVE-2026-56131 CVE-2026-56412 (2.8.2)
CVE-2026-72522 (2.8.3)
[1] https://github.com/libexpat/libexpat/blob/R_2_8_3/expat/Changes
[2] https://sourceware.org/libabigail/manual/abidiff.html
[3] https://github.com/nordix/meta-binaryaudit
Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../expat/expat/CVE-2026-41080-1.patch | 517 ------------------
.../expat/expat/CVE-2026-41080-2.patch | 33 --
.../expat/expat/CVE-2026-45186-01.patch | 70 ---
.../expat/expat/CVE-2026-45186-02.patch | 318 -----------
.../expat/expat/CVE-2026-45186-03.patch | 46 --
.../expat/expat/CVE-2026-45186-04.patch | 32 --
.../expat/expat/CVE-2026-45186-05.patch | 32 --
.../expat/expat/CVE-2026-45186-06.patch | 87 ---
.../expat/expat/CVE-2026-45186-07.patch | 52 --
.../expat/expat/CVE-2026-56132_p1.patch | 90 ---
.../expat/expat/CVE-2026-56132_p2.patch | 63 ---
.../expat/expat/CVE-2026-56132_p3.patch | 77 ---
.../expat/expat/CVE-2026-56132_p4.patch | 63 ---
.../expat/expat/CVE-2026-56132_p5.patch | 58 --
.../expat/expat/CVE-2026-56403_p1.patch | 83 ---
.../expat/expat/CVE-2026-56403_p2.patch | 40 --
.../expat/expat/CVE-2026-56404.patch | 47 --
.../expat/expat/CVE-2026-56405.patch | 32 --
.../expat/CVE-2026-56406-dependent.patch | 58 --
.../expat/expat/CVE-2026-56406.patch | 37 --
.../expat/expat/CVE-2026-56407.patch | 44 --
.../expat/expat/CVE-2026-56408.patch | 36 --
.../expat/expat/CVE-2026-56409.patch | 53 --
.../expat/expat/CVE-2026-56410_p1.patch | 40 --
.../expat/expat/CVE-2026-56410_p2.patch | 41 --
.../expat/expat/CVE-2026-56411.patch | 47 --
meta/recipes-core/expat/expat_2.7.5.bb | 62 ---
meta/recipes-core/expat/expat_2.8.3.bb | 33 ++
28 files changed, 33 insertions(+), 2158 deletions(-)
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-41080-1.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-41080-2.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-01.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-02.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-03.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-04.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-05.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-06.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-07.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56404.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56405.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56406.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56407.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56408.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56409.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch
delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56411.patch
delete mode 100644 meta/recipes-core/expat/expat_2.7.5.bb
create mode 100644 meta/recipes-core/expat/expat_2.8.3.bb
diff --git a/meta/recipes-core/expat/expat/CVE-2026-41080-1.patch b/meta/recipes-core/expat/expat/CVE-2026-41080-1.patch
deleted file mode 100644
index e93ad093f25..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-41080-1.patch
+++ /dev/null
@@ -1,517 +0,0 @@
-From fa1ebd60bfcc6d32f329803e5e837251e2387ed1 Mon Sep 17 00:00:00 2001
-From: Sebastian Pipping <sebastian@pipping.org>
-Date: Sun, 30 Mar 2025 19:26:55 +0200
-Subject: [PATCH v2 1/2] expat: fix CVE-2026-41080
-
-The existing hash flooding protection in libexpat (based on SipHash)
-only used 4 to 8 bytes of entropy for a salt, when 16 bytes are
-supported by the SipHash implementation. This allows attackers to more
-feasibly guess the hash salt and craft inputs that cause hash
-collisions, leading to denial of service.
-
-Backport upstream changes that:
-- Migrate hash salt storage to larger struct sipkey (128-bit)
-- Drop unused parameter from generate_hash_secret_salt
-- Drop unneeded void * casts in generate_hash_secret_salt
-- Extract full 16 bytes of entropy for hash flooding protection
-- Introduce internal flag m_hash_secret_salt_set
-- Remove now-dead get_hash_secret_salt function (copy_salt_to_sipkey
- accesses the struct directly)
-- Add XML_SetHashSalt16Bytes API function
-- Deprecate XML_SetHashSalt
-- Add symbol export in libexpat.map.in (LIBEXPAT_2.7.6)
-- Add backport feature macro XML_BACKPORT_SET_HASH_SALT_16_BYTES
-- Add test_hash_salt_setter unit test
-- Update documentation and Changes file
-
-Squashed backport of upstream PR #1183 commits 909201a8, bc193afc,
-08697a9b, f5eacefb, fa1ebd60, f76124e7, e3349d85, c8c5caf4,
-592d5fa3, 8ad3ef57, ec9fcd2e, and 8017e11e.
-
-CVE: CVE-2026-41080
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1183]
-Signed-off-by: Amaury Couderc <amaury.couderc@est.tech>
----
- Changes | 17 ++++++
- doc/reference.html | 55 +++++++++++++++++--
- lib/expat.h | 15 ++++++
- lib/internal.h | 2 +
- lib/libexpat.map.in | 5 ++
- lib/xmlparse.c | 124 +++++++++++++++++++++++++++++++++----------
- tests/basic_tests.c | 25 +++++++++
- 7 files changed, 212 insertions(+), 31 deletions(-)
-
-diff --git a/Changes b/Changes
-index 2b3704a6..1d8227ec 100644
---- a/Changes
-+++ b/Changes
-@@ -29,6 +29,23 @@
- !! THANK YOU! Sebastian Pipping -- Berlin, 2026-03-17 !!
- !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
-
-+Patches
-+ Security fixes:
-+ #47 #1183 CVE-2026-41080 -- The existing hash flooding protection
-+ (based on SipHash) only used 4 to 8 bytes of entropy for
-+ a salt, when 16 bytes of salt are supported by the
-+ implementation of SipHash used by Expat. Now full 16 bytes
-+ of entropy are used to improve protection against hash
-+ flooding attacks.
-+ Existing API function XML_SetHashSalt is now deprecated
-+ because of its limitations, and its use should be
-+ considered a vulnerability. Please either use the new API
-+ function XML_SetHashSalt16Bytes (with known-high-quality
-+ entropy input only!) instead, or leave the derivation of
-+ a 16-bytes hash salt from high quality entropy to Expat's
-+ internal machinery (by *not* calling either of the two
-+ XML_SetHashSalt* functions).
-+
- Release 2.7.5 Tue March 17 2026
- Security fixes:
- #1158 CVE-2026-32776 -- Fix NULL function pointer dereference for
-diff --git a/doc/reference.html b/doc/reference.html
-index 5faa8d65..64b9fd67 100644
---- a/doc/reference.html
-+++ b/doc/reference.html
-@@ -404,7 +404,11 @@
- </li>
-
- <li>
-- <a href="#XML_SetHashSalt">XML_SetHashSalt</a>
-+ <a href="#XML_SetHashSalt">XML_SetHashSalt</a> (deprecated)
-+ </li>
-+
-+ <li>
-+ <a href="#XML_SetHashSalt16Bytes">XML_SetHashSalt16Bytes</a>
- </li>
-
- <li>
-@@ -3449,22 +3453,35 @@ XML_SetParamEntityParsing(XML_Parser p,
- </div>
-
- <h4 id="XML_SetHashSalt">
-- XML_SetHashSalt
-+ XML_SetHashSalt (deprecated)
- </h4>
-
- <pre class="fcndec">
- int XMLCALL
--XML_SetHashSalt(XML_Parser p,
-+XML_SetHashSalt(XML_Parser parser,
- unsigned long hash_salt);
- </pre>
- <div class="fcndef">
- Sets the hash salt to use for internal hash calculations. Helps in preventing DoS
- attacks based on predicting hash function behavior. In order to have an effect
- this must be called before parsing has started. Returns 1 if successful, 0 when
-- called after <code>XML_Parse</code> or <code>XML_ParseBuffer</code>.
-+ called after <code>XML_Parse</code> or <code>XML_ParseBuffer</code> or when
-+ <code>parser</code> is <code>NULL</code>.
-+ <p>
-+ <b>Note:</b> Function <code>XML_SetHashSalt</code> is
-+ <strong>deprecated</strong>. Please use function <code><a href=
-+ "#XML_SetHashSalt16Bytes">XML_SetHashSalt16Bytes</a></code> instead for better
-+ security. <code>XML_SetHashSalt</code> only provides 4 to 8 bytes of entropy
-+ (depending on the size of type <code>unsigned long</code>) while the SipHash
-+ implementation used by Expat can leverage up to 16 bytes of entropy — at least
-+ twice as much. Function <code><a href=
-+ "#XML_SetHashSalt16Bytes">XML_SetHashSalt16Bytes</a></code> of Expat >=2.7.6
-+ (and where backported) matches the amount of entropy supported by SipHash.
-+ </p>
-+
- <p>
- <b>Note:</b> This call is optional, as the parser will auto-generate a new
-- random salt value if no value has been set at the start of parsing.
-+ random salt value internally if no value has been set by the start of parsing.
- </p>
-
- <p>
-@@ -3475,6 +3492,34 @@ XML_SetHashSalt(XML_Parser p,
- </p>
- </div>
-
-+ <h4 id="XML_SetHashSalt16Bytes">
-+ XML_SetHashSalt16Bytes
-+ </h4>
-+
-+ <pre class="fcndec">
-+/* Added in Expat 2.7.6. */
-+XML_Bool XMLCALL
-+XML_SetHashSalt16Bytes(XML_Parser parser,
-+ const uint8_t entropy[16]);
-+</pre>
-+ <div class="fcndef">
-+ Sets the hash salt to use for internal hash calculations. Helps in preventing DoS
-+ attacks based on predicting hash function behavior. In order to have an effect
-+ this must be called before parsing has started. Returns <code>XML_TRUE</code> if
-+ successful, <code>XML_FALSE</code> when called after <code>XML_Parse</code> or
-+ <code>XML_ParseBuffer</code> or when <code>parser</code> is <code>NULL</code>.
-+ <p>
-+ <b>Note:</b> Setting a salt that is <em>not</em> from a source of high quality
-+ entropy (like <code>getentropy(3)</code>) will make the parser vulnerable to
-+ hash flooding attacks.
-+ </p>
-+
-+ <p>
-+ <b>Note:</b> This call is optional, as the parser will auto-generate a new
-+ random salt value internally if no value has been set by the start of parsing.
-+ </p>
-+ </div>
-+
- <h4 id="XML_UseForeignDTD">
- XML_UseForeignDTD
- </h4>
-diff --git a/lib/expat.h b/lib/expat.h
-index 18dbaebd..7693f62c 100644
---- a/lib/expat.h
-+++ b/lib/expat.h
-@@ -45,6 +45,7 @@
- #ifndef Expat_INCLUDED
- # define Expat_INCLUDED 1
-
-+# include <stdint.h> // for uint8_t
- # include <stdlib.h>
- # include "expat_external.h"
-
-@@ -917,10 +918,25 @@ XML_SetParamEntityParsing(XML_Parser parser,
- function behavior. This must be called before parsing is started.
- Returns 1 if successful, 0 when called after parsing has started.
- Note: If parser == NULL, the function will do nothing and return 0.
-+ DEPRECATED since Expat 2.7.6.
- */
- XMLPARSEAPI(int)
- XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt);
-
-+/* Sets the hash salt to use for internal hash calculations.
-+ Helps in preventing DoS attacks based on predicting hash function behavior.
-+ This must be called before parsing is started.
-+ Returns XML_TRUE if successful, XML_FALSE when called after parsing has
-+ started or when parser is NULL.
-+ Added in Expat 2.7.6.
-+*/
-+XMLPARSEAPI(XML_Bool)
-+XML_SetHashSalt16Bytes(XML_Parser parser, const uint8_t entropy[16]);
-+
-+/* Backport feature macro: signals that XML_SetHashSalt16Bytes is available
-+ even though XML_COMBINED_VERSION < 20800. */
-+# define XML_BACKPORT_SET_HASH_SALT_16_BYTES 1
-+
- /* If XML_Parse or XML_ParseBuffer have returned XML_STATUS_ERROR, then
- XML_GetErrorCode returns information about the error.
- */
-diff --git a/lib/internal.h b/lib/internal.h
-index 61266ebb..1995c17b 100644
---- a/lib/internal.h
-+++ b/lib/internal.h
-@@ -113,6 +113,7 @@
- #if defined(_WIN32) \
- && (! defined(__USE_MINGW_ANSI_STDIO) \
- || (1 - __USE_MINGW_ANSI_STDIO - 1 == 0))
-+# define EXPAT_FMT_LLX(midpart) "%" midpart "I64x"
- # define EXPAT_FMT_ULL(midpart) "%" midpart "I64u"
- # if defined(_WIN64) // Note: modifiers "td" and "zu" do not work for MinGW
- # define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart "I64d"
-@@ -122,6 +123,7 @@
- # define EXPAT_FMT_SIZE_T(midpart) "%" midpart "u"
- # endif
- #else
-+# define EXPAT_FMT_LLX(midpart) "%" midpart "llx"
- # define EXPAT_FMT_ULL(midpart) "%" midpart "llu"
- # if ! defined(ULONG_MAX)
- # error Compiler did not define ULONG_MAX for us
-diff --git a/lib/libexpat.map.in b/lib/libexpat.map.in
-index 52e59ed3..8527eb54 100644
---- a/lib/libexpat.map.in
-+++ b/lib/libexpat.map.in
-@@ -117,3 +117,8 @@ LIBEXPAT_2.7.2 {
- @_EXPAT_COMMENT_DTD_OR_GE@ XML_SetAllocTrackerActivationThreshold;
- @_EXPAT_COMMENT_DTD_OR_GE@ XML_SetAllocTrackerMaximumAmplification;
- } LIBEXPAT_2.6.0;
-+
-+LIBEXPAT_2.7.6 {
-+ global:
-+ XML_SetHashSalt16Bytes;
-+} LIBEXPAT_2.7.2;
-diff --git a/lib/xmlparse.c b/lib/xmlparse.c
-index 0248b665..75a7e5d0 100644
---- a/lib/xmlparse.c
-+++ b/lib/xmlparse.c
-@@ -604,7 +604,7 @@ static ELEMENT_TYPE *getElementType(XML_Parser parser, const ENCODING *enc,
-
- static XML_Char *copyString(const XML_Char *s, XML_Parser parser);
-
--static unsigned long generate_hash_secret_salt(XML_Parser parser);
-+static struct sipkey generate_hash_secret_salt(void);
- static XML_Bool startParsing(XML_Parser parser);
-
- static XML_Parser parserCreate(const XML_Char *encodingName,
-@@ -777,7 +777,8 @@ struct XML_ParserStruct {
- XML_Bool m_useForeignDTD;
- enum XML_ParamEntityParsing m_paramEntityParsing;
- #endif
-- unsigned long m_hash_secret_salt;
-+ struct sipkey m_hash_secret_salt_128;
-+ XML_Bool m_hash_secret_salt_set;
- #if XML_GE == 1
- ACCOUNTING m_accounting;
- MALLOC_TRACKER m_alloc_tracker;
-@@ -1192,69 +1193,65 @@ gather_time_entropy(void) {
-
- #endif /* ! defined(HAVE_ARC4RANDOM_BUF) && ! defined(HAVE_ARC4RANDOM) */
-
--static unsigned long
--ENTROPY_DEBUG(const char *label, unsigned long entropy) {
-+static struct sipkey
-+ENTROPY_DEBUG(const char *label, struct sipkey entropy_128) {
- if (getDebugLevel("EXPAT_ENTROPY_DEBUG", 0) >= 1u) {
-- fprintf(stderr, "expat: Entropy: %s --> 0x%0*lx (%lu bytes)\n", label,
-- (int)sizeof(entropy) * 2, entropy, (unsigned long)sizeof(entropy));
-+ fprintf(stderr,
-+ "expat: Entropy: %s --> [0x" EXPAT_FMT_LLX(
-+ "016") ", 0x" EXPAT_FMT_LLX("016") "] (16 bytes)\n",
-+ label, (unsigned long long)entropy_128.k[0],
-+ (unsigned long long)entropy_128.k[1]);
- }
-- return entropy;
-+ return entropy_128;
- }
-
--static unsigned long
--generate_hash_secret_salt(XML_Parser parser) {
-- unsigned long entropy;
-- (void)parser;
-+static struct sipkey
-+generate_hash_secret_salt(void) {
-+ struct sipkey entropy;
-
- /* "Failproof" high quality providers: */
- #if defined(HAVE_ARC4RANDOM_BUF)
- arc4random_buf(&entropy, sizeof(entropy));
- return ENTROPY_DEBUG("arc4random_buf", entropy);
- #elif defined(HAVE_ARC4RANDOM)
-- writeRandomBytes_arc4random((void *)&entropy, sizeof(entropy));
-+ writeRandomBytes_arc4random(&entropy, sizeof(entropy));
- return ENTROPY_DEBUG("arc4random", entropy);
- #else
- /* Try high quality providers first .. */
- # ifdef _WIN32
-- if (writeRandomBytes_rand_s((void *)&entropy, sizeof(entropy))) {
-+ if (writeRandomBytes_rand_s(&entropy, sizeof(entropy))) {
- return ENTROPY_DEBUG("rand_s", entropy);
- }
- # elif defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM)
-- if (writeRandomBytes_getrandom_nonblock((void *)&entropy, sizeof(entropy))) {
-+ if (writeRandomBytes_getrandom_nonblock(&entropy, sizeof(entropy))) {
- return ENTROPY_DEBUG("getrandom", entropy);
- }
- # endif
- # if ! defined(_WIN32) && defined(XML_DEV_URANDOM)
-- if (writeRandomBytes_dev_urandom((void *)&entropy, sizeof(entropy))) {
-+ if (writeRandomBytes_dev_urandom(&entropy, sizeof(entropy))) {
- return ENTROPY_DEBUG("/dev/urandom", entropy);
- }
- # endif /* ! defined(_WIN32) && defined(XML_DEV_URANDOM) */
- /* .. and self-made low quality for backup: */
-
-- entropy = gather_time_entropy();
-+ entropy.k[0] = 0;
-+ entropy.k[1] = gather_time_entropy();
- # if ! defined(__wasi__)
- /* Process ID is 0 bits entropy if attacker has local access */
-- entropy ^= getpid();
-+ entropy.k[1] ^= getpid();
- # endif
-
- /* Factors are 2^31-1 and 2^61-1 (Mersenne primes M31 and M61) */
- if (sizeof(unsigned long) == 4) {
-- return ENTROPY_DEBUG("fallback(4)", entropy * 2147483647);
-+ entropy.k[1] *= 2147483647;
-+ return ENTROPY_DEBUG("fallback(4)", entropy);
- } else {
-- return ENTROPY_DEBUG("fallback(8)",
-- entropy * (unsigned long)2305843009213693951ULL);
-+ entropy.k[1] *= 2305843009213693951ULL;
-+ return ENTROPY_DEBUG("fallback(8)", entropy);
- }
- #endif
- }
-
--static unsigned long
--get_hash_secret_salt(XML_Parser parser) {
-- const XML_Parser rootParser = getRootParserOf(parser, NULL);
-- assert(! rootParser->m_parentParser);
--
-- return rootParser->m_hash_secret_salt;
--}
--
- static enum XML_Error
- callProcessor(XML_Parser parser, const char *start, const char *end,
- const char **endPtr) {
-@@ -1323,8 +1320,10 @@ callProcessor(XML_Parser parser, const char *start, const char *end,
- static XML_Bool /* only valid for root parser */
- startParsing(XML_Parser parser) {
- /* hash functions must be initialized before setContext() is called */
-- if (parser->m_hash_secret_salt == 0)
-- parser->m_hash_secret_salt = generate_hash_secret_salt(parser);
-+ if (parser->m_hash_secret_salt_set != XML_TRUE) {
-+ parser->m_hash_secret_salt_128 = generate_hash_secret_salt();
-+ parser->m_hash_secret_salt_set = XML_TRUE;
-+ }
- if (parser->m_ns) {
- /* implicit context only set for root parser, since child
- parsers (i.e. external entity parsers) will inherit it
-@@ -1612,7 +1611,9 @@ parserInit(XML_Parser parser, const XML_Char *encodingName) {
- parser->m_useForeignDTD = XML_FALSE;
- parser->m_paramEntityParsing = XML_PARAM_ENTITY_PARSING_NEVER;
- #endif
-- parser->m_hash_secret_salt = 0;
-+ parser->m_hash_secret_salt_128.k[0] = 0;
-+ parser->m_hash_secret_salt_128.k[1] = 0;
-+ parser->m_hash_secret_salt_set = XML_FALSE;
-
- #if XML_GE == 1
- memset(&parser->m_accounting, 0, sizeof(ACCOUNTING));
-@@ -1779,7 +1780,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context,
- from hash tables associated with either parser without us having
- to worry which hash secrets each table has.
- */
-- unsigned long oldhash_secret_salt;
-+ struct sipkey oldhash_secret_salt_128;
-+ XML_Bool oldhash_secret_salt_set;
- XML_Bool oldReparseDeferralEnabled;
-
- /* Validate the oldParser parameter before we pull everything out of it */
-@@ -1825,7 +1827,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context,
- from hash tables associated with either parser without us having
- to worry which hash secrets each table has.
- */
-- oldhash_secret_salt = parser->m_hash_secret_salt;
-+ oldhash_secret_salt_128 = parser->m_hash_secret_salt_128;
-+ oldhash_secret_salt_set = parser->m_hash_secret_salt_set;
- oldReparseDeferralEnabled = parser->m_reparseDeferralEnabled;
-
- #ifdef XML_DTD
-@@ -1880,7 +1883,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context,
- parser->m_externalEntityRefHandlerArg = oldExternalEntityRefHandlerArg;
- parser->m_defaultExpandInternalEntities = oldDefaultExpandInternalEntities;
- parser->m_ns_triplets = oldns_triplets;
-- parser->m_hash_secret_salt = oldhash_secret_salt;
-+ parser->m_hash_secret_salt_128 = oldhash_secret_salt_128;
-+ parser->m_hash_secret_salt_set = oldhash_secret_salt_set;
- parser->m_reparseDeferralEnabled = oldReparseDeferralEnabled;
- parser->m_parentParser = oldParser;
- #ifdef XML_DTD
-@@ -2327,6 +2331,7 @@ XML_SetParamEntityParsing(XML_Parser parser,
- #endif
- }
-
-+// DEPRECATED since Expat 2.7.6.
- int XMLCALL
- XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) {
- if (parser == NULL)
-@@ -2337,10 +2342,46 @@ XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) {
- /* block after XML_Parse()/XML_ParseBuffer() has been called */
- if (parserBusy(rootParser))
- return 0;
-- rootParser->m_hash_secret_salt = hash_salt;
-+
-+ rootParser->m_hash_secret_salt_128.k[0] = 0;
-+ rootParser->m_hash_secret_salt_128.k[1] = hash_salt;
-+
-+ if (hash_salt != 0) { // to remain backwards compatible
-+ rootParser->m_hash_secret_salt_set = XML_TRUE;
-+
-+ if (sizeof(unsigned long) == 4)
-+ ENTROPY_DEBUG("explicit(4)", rootParser->m_hash_secret_salt_128);
-+ else
-+ ENTROPY_DEBUG("explicit(8)", rootParser->m_hash_secret_salt_128);
-+ }
-+
- return 1;
- }
-
-+XML_Bool XMLCALL
-+XML_SetHashSalt16Bytes(XML_Parser parser, const uint8_t entropy[16]) {
-+ if (parser == NULL)
-+ return XML_FALSE;
-+
-+ if (entropy == NULL)
-+ return XML_FALSE;
-+
-+ const XML_Parser rootParser = getRootParserOf(parser, NULL);
-+ assert(! rootParser->m_parentParser);
-+
-+ /* block after XML_Parse()/XML_ParseBuffer() has been called */
-+ if (parserBusy(rootParser))
-+ return XML_FALSE;
-+
-+ sip_tokey(&(rootParser->m_hash_secret_salt_128), entropy);
-+
-+ rootParser->m_hash_secret_salt_set = XML_TRUE;
-+
-+ ENTROPY_DEBUG("explicit(16)", rootParser->m_hash_secret_salt_128);
-+
-+ return XML_TRUE;
-+}
-+
- enum XML_Status XMLCALL
- XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) {
- if ((parser == NULL) || (len < 0) || ((s == NULL) && (len != 0))) {
-@@ -7842,8 +7883,10 @@ keylen(KEY s) {
-
- static void
- copy_salt_to_sipkey(XML_Parser parser, struct sipkey *key) {
-- key->k[0] = 0;
-- key->k[1] = get_hash_secret_salt(parser);
-+ const XML_Parser rootParser = getRootParserOf(parser, NULL);
-+ assert(! rootParser->m_parentParser);
-+
-+ *key = rootParser->m_hash_secret_salt_128;
- }
-
- static unsigned long FASTCALL
-diff --git a/tests/basic_tests.c b/tests/basic_tests.c
-index 02d1d5fd..26662fee 100644
---- a/tests/basic_tests.c
-+++ b/tests/basic_tests.c
-@@ -204,6 +204,30 @@ START_TEST(test_hash_collision) {
- END_TEST
- #undef COLLIDING_HASH_SALT
-
-+START_TEST(test_hash_salt_setter) {
-+ const uint8_t entropy[16] = {'0', '1', '2', '3', '4', '5', '6', '7',
-+ '8', '9', 'a', 'b', 'c', 'd', 'e', 'f'};
-+ XML_Parser parser = XML_ParserCreate(NULL);
-+
-+ // NULL parser should be rejected
-+ assert_true(XML_SetHashSalt16Bytes(NULL, entropy) == XML_FALSE);
-+
-+ // NULL entropy should be rejected
-+ assert_true(XML_SetHashSalt16Bytes(parser, NULL) == XML_FALSE);
-+
-+ // Setting should be allowed more than once
-+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_TRUE);
-+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_TRUE);
-+
-+ // But not after parsing has started
-+ assert_true(XML_Parse(parser, "", 0, XML_FALSE /* isFinal */)
-+ == XML_STATUS_OK);
-+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_FALSE);
-+
-+ XML_ParserFree(parser);
-+}
-+END_TEST
-+
- /* Regression test for SF bug #491986. */
- START_TEST(test_danish_latin1) {
- const char *text = "<?xml version='1.0' encoding='iso-8859-1'?>\n"
-@@ -6292,6 +6316,7 @@ make_basic_test_case(Suite *s) {
- tcase_add_test(tc_basic, test_bom_utf16_le);
- tcase_add_test(tc_basic, test_nobom_utf16_le);
- tcase_add_test(tc_basic, test_hash_collision);
-+ tcase_add_test(tc_basic, test_hash_salt_setter);
- tcase_add_test(tc_basic, test_illegal_utf8);
- tcase_add_test(tc_basic, test_utf8_auto_align);
- tcase_add_test(tc_basic, test_utf16);
---
-2.34.1
diff --git a/meta/recipes-core/expat/expat/CVE-2026-41080-2.patch b/meta/recipes-core/expat/expat/CVE-2026-41080-2.patch
deleted file mode 100644
index 0410f8b070f..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-41080-2.patch
+++ /dev/null
@@ -1,33 +0,0 @@
-From 3cdd1df2644388aff25dd0ed7128c7bb1de1a7d8 Mon Sep 17 00:00:00 2001
-From: Christoph Reiter <reiter.christoph@gmail.com>
-Date: Wed, 10 Jun 2026 21:27:51 +0200
-Subject: [PATCH 2/2] cmake|windows: add missing export for new
- XML_SetHashSalt16Bytes
-
-A new XML_SetHashSalt16Bytes symbol was added in #1183, but it
-wasn't added to the def file, so the export is missing when building
-libexpat on Windows with cmake.
-
-Add the new symbol to the .def template.
-
-CVE: CVE-2026-41080
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/3cdd1df2644388aff25dd0ed7128c7bb1de1a7d8]
-
-Signed-off-by: Christoph Reiter <reiter.christoph@gmail.com>
-Signed-off-by: Amaury Couderc <amaury.couderc@est.tech>
----
- lib/libexpat.def.cmake | 2 ++
- 1 file changed, 2 insertions(+)
-
-diff --git a/lib/libexpat.def.cmake b/lib/libexpat.def.cmake
-index 9b9e22cb..948135a5 100644
---- a/lib/libexpat.def.cmake
-+++ b/lib/libexpat.def.cmake
-@@ -83,3 +83,5 @@ EXPORTS
- ; added with version 2.7.2
- @_EXPAT_COMMENT_DTD_OR_GE@ XML_SetAllocTrackerMaximumAmplification @72
- @_EXPAT_COMMENT_DTD_OR_GE@ XML_SetAllocTrackerActivationThreshold @73
-+; added with version 2.7.6
-+ XML_SetHashSalt16Bytes @74
---
-2.34.1
diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch
deleted file mode 100644
index 478978f4ca2..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch
+++ /dev/null
@@ -1,70 +0,0 @@
-From b659bf974f29b991870ba1f66af687c73e07fbf8 Mon Sep 17 00:00:00 2001
-From: =?UTF-8?q?Berkay=20Eren=20=C3=9Cr=C3=BCn?= <berkay.ueruen@siemens.com>
-Date: Fri, 13 Mar 2026 13:26:45 +0100
-Subject: [PATCH 1/7] Make "counting_start_element_handler" count default attrs
-
-(cherry picked from commit 0802a5892030610144b736dec6e2f63e8600fe85)
-
-CVE: CVE-2026-45186
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/0802a5892030610144b736dec6e2f63e8600fe85]
-Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
----
- tests/basic_tests.c | 8 ++++----
- tests/handlers.c | 2 +-
- tests/handlers.h | 1 +
- 3 files changed, 6 insertions(+), 5 deletions(-)
-
-diff --git a/tests/basic_tests.c b/tests/basic_tests.c
-index 02d1d5f..8c025a2 100644
---- a/tests/basic_tests.c
-+++ b/tests/basic_tests.c
-@@ -2466,9 +2466,9 @@ START_TEST(test_attributes) {
- {XCS("id"), XCS("one")},
- {NULL, NULL}};
- AttrInfo tag_info[] = {{XCS("c"), XCS("3")}, {NULL, NULL}};
-- ElementInfo info[] = {{XCS("doc"), 3, XCS("id"), NULL},
-- {XCS("tag"), 1, NULL, NULL},
-- {NULL, 0, NULL, NULL}};
-+ ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), NULL},
-+ {XCS("tag"), 1, 0, NULL, NULL},
-+ {NULL, 0, 0, NULL, NULL}};
- info[0].attributes = doc_info;
- info[1].attributes = tag_info;
-
-@@ -5543,7 +5543,7 @@ START_TEST(test_deep_nested_attribute_entity) {
- (long unsigned)(N_LINES - 1));
-
- AttrInfo doc_info[] = {{XCS("name"), XCS("deepText")}, {NULL, NULL}};
-- ElementInfo info[] = {{XCS("foo"), 1, NULL, NULL}, {NULL, 0, NULL, NULL}};
-+ ElementInfo info[] = {{XCS("foo"), 1, 0, NULL, NULL}, {NULL, 0, 0, NULL, NULL}};
- info[0].attributes = doc_info;
-
- XML_Parser parser = XML_ParserCreate(NULL);
-diff --git a/tests/handlers.c b/tests/handlers.c
-index e456df2..bd1b54e 100644
---- a/tests/handlers.c
-+++ b/tests/handlers.c
-@@ -137,7 +137,7 @@ counting_start_element_handler(void *userData, const XML_Char *name,
- fail("ID does not have the correct name");
- return;
- }
-- for (i = 0; i < info->attr_count; i++) {
-+ for (i = 0; i < info->attr_count + info->default_attr_count; i++) {
- attr = info->attributes;
- while (attr->name != NULL) {
- if (! xcstrcmp(atts[0], attr->name))
-diff --git a/tests/handlers.h b/tests/handlers.h
-index fcde27a..27a53f2 100644
---- a/tests/handlers.h
-+++ b/tests/handlers.h
-@@ -88,6 +88,7 @@ typedef struct attrInfo {
- typedef struct elementInfo {
- const XML_Char *name;
- int attr_count;
-+ int default_attr_count;
- const XML_Char *id_name;
- AttrInfo *attributes;
- } ElementInfo;
---
-2.43.0
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch
deleted file mode 100644
index 6c90e15b47d..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch
+++ /dev/null
@@ -1,318 +0,0 @@
-From 32848241057dfaa4c68fae475f51fbe1a182c004 Mon Sep 17 00:00:00 2001
-From: =?UTF-8?q?Berkay=20Eren=20=C3=9Cr=C3=BCn?= <berkay.ueruen@siemens.com>
-Date: Fri, 13 Mar 2026 13:27:31 +0100
-Subject: [PATCH 2/7] test(attlist): Cover duplicate attribute names
-
-Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
-(cherry picked from commit e569f47181c43dca5d262089e541ddf9a9c09927)
-
-CVE: CVE-2026-45186
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/e569f47181c43dca5d262089e541ddf9a9c09927]
-Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
----
- tests/basic_tests.c | 282 ++++++++++++++++++++++++++++++++++++++++++++
- 1 file changed, 282 insertions(+)
-
-diff --git a/tests/basic_tests.c b/tests/basic_tests.c
-index 8c025a2..83c453c 100644
---- a/tests/basic_tests.c
-+++ b/tests/basic_tests.c
-@@ -2489,6 +2489,279 @@ START_TEST(test_attributes) {
- }
- END_TEST
-
-+START_TEST(test_duplicate_cdata_attribute) {
-+ /*
-+ https://www.w3.org/TR/xml/#attdecls
-+
-+ Test the following statement from the linked specification:
-+ When more than one definition is provided for the same attribute of a given
-+ element type, the first declaration is binding and later declarations are
-+ ignored.
-+ */
-+
-+ const char *text
-+ = "<!DOCTYPE doc [\n"
-+ " <!ATTLIST doc attribute CDATA 'expected' attribute CDATA 'ignored'>\n"
-+ "]>\n"
-+ "<doc/>\n";
-+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected")}, {NULL, NULL}};
-+ ElementInfo info[]
-+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
-+
-+ XML_Parser parser = XML_ParserCreate(NULL);
-+ assert_true(parser != NULL);
-+
-+ ParserAndElementInfo parserAndElementInfos = {
-+ parser,
-+ info,
-+ };
-+
-+ XML_SetStartElementHandler(parser, counting_start_element_handler);
-+ XML_SetUserData(parser, &parserAndElementInfos);
-+
-+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
-+ != XML_STATUS_OK)
-+ xml_failure(parser);
-+
-+ XML_ParserFree(parser);
-+}
-+END_TEST
-+
-+START_TEST(test_duplicate_id_attribute_1) {
-+ /*
-+ https://www.w3.org/TR/xml/#attdecls
-+
-+ Test the following statement from the linked specification:
-+ When more than one definition is provided for the same attribute of a given
-+ element type, the first declaration is binding and later declarations are
-+ ignored.
-+ */
-+
-+ const char *text
-+ = "<!DOCTYPE doc [\n"
-+ " <!ATTLIST doc identifier CDATA 'expected' identifier ID #REQUIRED>\n"
-+ "]>\n"
-+ "<doc/>\n";
-+ AttrInfo doc_info[] = {{XCS("identifier"), XCS("expected")}, {NULL, NULL}};
-+ ElementInfo info[]
-+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
-+
-+ XML_Parser parser = XML_ParserCreate(NULL);
-+ assert_true(parser != NULL);
-+
-+ ParserAndElementInfo parserAndElementInfos = {
-+ parser,
-+ info,
-+ };
-+
-+ XML_SetStartElementHandler(parser, counting_start_element_handler);
-+ XML_SetUserData(parser, &parserAndElementInfos);
-+
-+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
-+ != XML_STATUS_OK)
-+ xml_failure(parser);
-+
-+ XML_ParserFree(parser);
-+}
-+END_TEST
-+
-+START_TEST(test_duplicate_id_attribute_2) {
-+ /*
-+ https://www.w3.org/TR/xml/#attdecls
-+
-+ Test the following statement from the linked specification:
-+ When more than one definition is provided for the same attribute of a given
-+ element type, the first declaration is binding and later declarations are
-+ ignored.
-+ */
-+
-+ const char *text
-+ = "<!DOCTYPE doc [\n"
-+ " <!ATTLIST doc identifier ID #REQUIRED identifier CDATA 'unexpected'>\n"
-+ "]>\n"
-+ "<doc/>\n";
-+ AttrInfo doc_info[] = {{NULL, NULL}};
-+
-+ ElementInfo info[]
-+ = {{XCS("doc"), 0, 0, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
-+
-+ XML_Parser parser = XML_ParserCreate(NULL);
-+ assert_true(parser != NULL);
-+
-+ ParserAndElementInfo parserAndElementInfos = {
-+ parser,
-+ info,
-+ };
-+
-+ XML_SetStartElementHandler(parser, counting_start_element_handler);
-+ XML_SetUserData(parser, &parserAndElementInfos);
-+
-+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
-+ != XML_STATUS_OK)
-+ xml_failure(parser);
-+
-+ XML_ParserFree(parser);
-+}
-+END_TEST
-+
-+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl) {
-+ /*
-+ https://www.w3.org/TR/xml/#attdecls
-+
-+ Test the following statement from the linked specification:
-+ When more than one AttlistDecl is provided for a given element type,
-+ the contents of all those provided are merged.
-+ */
-+ const char *text = "<!DOCTYPE doc [\n"
-+ " <!ATTLIST doc attribute CDATA 'expected'>\n"
-+ " <!ATTLIST doc attribute CDATA 'ignored'>\n"
-+ "]>\n"
-+ "<doc/>\n";
-+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected")}, {NULL, NULL}};
-+ ElementInfo info[]
-+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
-+
-+ XML_Parser parser = XML_ParserCreate(NULL);
-+ assert_true(parser != NULL);
-+
-+ ParserAndElementInfo parserAndElementInfos = {
-+ parser,
-+ info,
-+ };
-+
-+ XML_SetStartElementHandler(parser, counting_start_element_handler);
-+ XML_SetUserData(parser, &parserAndElementInfos);
-+
-+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
-+ != XML_STATUS_OK)
-+ xml_failure(parser);
-+
-+ XML_ParserFree(parser);
-+}
-+END_TEST
-+
-+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl_2) {
-+ /*
-+ https://www.w3.org/TR/xml/#attdecls
-+
-+ Test the following statement from the linked specification:
-+ When more than one AttlistDecl is provided for a given element type,
-+ the contents of all those provided are merged.
-+ */
-+ const char *text = "<!DOCTYPE doc [\n"
-+ " <!ATTLIST doc attribute CDATA 'expected_doc'>\n"
-+ " <!ATTLIST tag attribute CDATA 'expected_tag'>\n"
-+ " <!ATTLIST doc attribute CDATA 'ignored_doc'>\n"
-+ "]>\n"
-+ "<doc><tag></tag></doc>\n";
-+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected_doc")}, {NULL, NULL}};
-+ AttrInfo tag_info[] = {{XCS("attribute"), XCS("expected_tag")}, {NULL, NULL}};
-+ ElementInfo info[] = {{XCS("doc"), 0, 1, NULL, doc_info},
-+ {XCS("tag"), 0, 1, NULL, tag_info},
-+ {NULL, 0, 0, NULL, NULL}};
-+
-+ XML_Parser parser = XML_ParserCreate(NULL);
-+ assert_true(parser != NULL);
-+
-+ ParserAndElementInfo parserAndElementInfos = {
-+ parser,
-+ info,
-+ };
-+
-+ XML_SetStartElementHandler(parser, counting_start_element_handler);
-+ XML_SetUserData(parser, &parserAndElementInfos);
-+
-+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
-+ != XML_STATUS_OK)
-+ xml_failure(parser);
-+
-+ XML_ParserFree(parser);
-+}
-+END_TEST
-+
-+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl_3) {
-+ /*
-+ https://www.w3.org/TR/xml/#attdecls
-+
-+ Test the following statement from the linked specification:
-+ When more than one AttlistDecl is provided for a given element type,
-+ the contents of all those provided are merged.
-+ */
-+ const char *text
-+ = "<!DOCTYPE doc [\n"
-+ " <!ATTLIST doc attribute CDATA 'expected_doc'>\n"
-+ " <!ATTLIST tag attribute CDATA 'expected_tag'>\n"
-+ " <!ATTLIST doc second_attribute CDATA 'second_expected_doc' attribute CDATA 'ignored_doc'>\n"
-+ "]>\n"
-+ "<doc><tag></tag></doc>\n";
-+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected_doc")},
-+ {XCS("second_attribute"), XCS("second_expected_doc")},
-+ {NULL, NULL}};
-+ AttrInfo tag_info[] = {{XCS("attribute"), XCS("expected_tag")}, {NULL, NULL}};
-+ ElementInfo info[] = {{XCS("doc"), 0, 2, NULL, doc_info},
-+ {XCS("tag"), 0, 1, NULL, tag_info},
-+ {NULL, 0, 0, NULL, NULL}};
-+
-+ XML_Parser parser = XML_ParserCreate(NULL);
-+ assert_true(parser != NULL);
-+
-+ ParserAndElementInfo parserAndElementInfos = {
-+ parser,
-+ info,
-+ };
-+
-+ XML_SetStartElementHandler(parser, counting_start_element_handler);
-+ XML_SetUserData(parser, &parserAndElementInfos);
-+
-+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
-+ != XML_STATUS_OK)
-+ xml_failure(parser);
-+
-+ XML_ParserFree(parser);
-+}
-+END_TEST
-+
-+START_TEST(test_duplicate_id_attribute_multiple_attlistdecl) {
-+ /*
-+ https://www.w3.org/TR/xml/#attdecls
-+
-+ Test the following statement from the linked specification:
-+ When more than one AttlistDecl is provided for a given element type,
-+ the contents of all those provided are merged.
-+ */
-+ const char *text = "<!DOCTYPE doc [\n"
-+ " <!ATTLIST doc identifier ID #REQUIRED>\n"
-+ " <!ATTLIST tag identifier CDATA 'identifier_tag'>\n"
-+ " <!ATTLIST doc identifier CDATA 'ignored'>\n"
-+ "]>\n"
-+ "<doc identifier='doc_identity'><tag></tag></doc>\n";
-+ AttrInfo doc_info[]
-+ = {{XCS("identifier"), XCS("doc_identity")}, {NULL, NULL}};
-+ AttrInfo tag_info[]
-+ = {{XCS("identifier"), XCS("identifier_tag")}, {NULL, NULL}};
-+ ElementInfo info[] = {{XCS("doc"), 1, 0, XCS("identifier"), doc_info},
-+ {XCS("tag"), 0, 1, NULL, tag_info},
-+ {NULL, 0, 0, NULL, NULL}};
-+
-+ XML_Parser parser = XML_ParserCreate(NULL);
-+ assert_true(parser != NULL);
-+
-+ ParserAndElementInfo parserAndElementInfos = {
-+ parser,
-+ info,
-+ };
-+
-+ XML_SetStartElementHandler(parser, counting_start_element_handler);
-+ XML_SetUserData(parser, &parserAndElementInfos);
-+
-+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
-+ != XML_STATUS_OK)
-+ xml_failure(parser);
-+
-+ XML_ParserFree(parser);
-+}
-+END_TEST
-+
- /* Test reset works correctly in the middle of processing an internal
- * entity. Exercises some obscure code in XML_ParserReset().
- */
-@@ -6374,6 +6647,15 @@ make_basic_test_case(Suite *s) {
- tcase_add_test__ifdef_xml_dtd(tc_basic, test_empty_foreign_dtd);
- tcase_add_test(tc_basic, test_set_base);
- tcase_add_test(tc_basic, test_attributes);
-+ tcase_add_test(tc_basic, test_duplicate_cdata_attribute);
-+ tcase_add_test(tc_basic, test_duplicate_id_attribute_1);
-+ tcase_add_test(tc_basic, test_duplicate_id_attribute_2);
-+ tcase_add_test(tc_basic, test_duplicate_cdata_attribute_multiple_attlistdecl);
-+ tcase_add_test(tc_basic,
-+ test_duplicate_cdata_attribute_multiple_attlistdecl_2);
-+ tcase_add_test(tc_basic,
-+ test_duplicate_cdata_attribute_multiple_attlistdecl_3);
-+ tcase_add_test(tc_basic, test_duplicate_id_attribute_multiple_attlistdecl);
- tcase_add_test__if_xml_ge(tc_basic, test_reset_in_entity);
- tcase_add_test(tc_basic, test_resume_invalid_parse);
- tcase_add_test(tc_basic, test_resume_resuspended);
---
-2.43.0
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch
deleted file mode 100644
index f3b0614b8df..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch
+++ /dev/null
@@ -1,46 +0,0 @@
-From 468d6f44264e7ad73f3045f6487baccc846014e6 Mon Sep 17 00:00:00 2001
-From: Sebastian Pipping <sebastian@pipping.org>
-Date: Mon, 20 Apr 2026 13:44:43 +0200
-Subject: [PATCH 3/7] tests: Define .attributes the first time around
-
-(cherry picked from commit 05307d352a5aa858cdda57ec53a53b597b3a4a82)
-
-CVE: CVE-2026-45186
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/05307d352a5aa858cdda57ec53a53b597b3a4a82]
-Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
----
- tests/basic_tests.c | 10 ++++------
- 1 file changed, 4 insertions(+), 6 deletions(-)
-
-diff --git a/tests/basic_tests.c b/tests/basic_tests.c
-index 83c453c..810ff5e 100644
---- a/tests/basic_tests.c
-+++ b/tests/basic_tests.c
-@@ -2466,11 +2466,9 @@ START_TEST(test_attributes) {
- {XCS("id"), XCS("one")},
- {NULL, NULL}};
- AttrInfo tag_info[] = {{XCS("c"), XCS("3")}, {NULL, NULL}};
-- ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), NULL},
-- {XCS("tag"), 1, 0, NULL, NULL},
-+ ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), doc_info},
-+ {XCS("tag"), 1, 0, NULL, tag_info},
- {NULL, 0, 0, NULL, NULL}};
-- info[0].attributes = doc_info;
-- info[1].attributes = tag_info;
-
- XML_Parser parser = XML_ParserCreate(NULL);
- assert_true(parser != NULL);
-@@ -5816,8 +5814,8 @@ START_TEST(test_deep_nested_attribute_entity) {
- (long unsigned)(N_LINES - 1));
-
- AttrInfo doc_info[] = {{XCS("name"), XCS("deepText")}, {NULL, NULL}};
-- ElementInfo info[] = {{XCS("foo"), 1, 0, NULL, NULL}, {NULL, 0, 0, NULL, NULL}};
-- info[0].attributes = doc_info;
-+ ElementInfo info[]
-+ = {{XCS("foo"), 1, 0, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
-
- XML_Parser parser = XML_ParserCreate(NULL);
- ParserAndElementInfo parserPlusElemenInfo = {parser, info};
---
-2.43.0
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch
deleted file mode 100644
index d30ffa3f512..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch
+++ /dev/null
@@ -1,32 +0,0 @@
-From 0582bcabb773d4600d7c85516132b016f0163deb Mon Sep 17 00:00:00 2001
-From: Sebastian Pipping <sebastian@pipping.org>
-Date: Mon, 13 Apr 2026 01:34:03 +0200
-Subject: [PATCH 4/7] tests: Make counting_start_element_handler enforce
- complete attribute lists
-
-(cherry picked from commit 4176aff73840711060913e0ac6aa1168d8ba5c8d)
-
-CVE: CVE-2026-45186
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/4176aff73840711060913e0ac6aa1168d8ba5c8d]
-Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
----
- tests/handlers.c | 3 +++
- 1 file changed, 3 insertions(+)
-
-diff --git a/tests/handlers.c b/tests/handlers.c
-index bd1b54e..8cda3a8 100644
---- a/tests/handlers.c
-+++ b/tests/handlers.c
-@@ -155,6 +155,9 @@ counting_start_element_handler(void *userData, const XML_Char *name,
- /* Remember, two entries in atts per attribute (see above) */
- atts += 2;
- }
-+
-+ // Self-test that the test case's list of expected attributes is complete
-+ assert_true(atts[0] == NULL);
- }
-
- void XMLCALL
---
-2.43.0
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch
deleted file mode 100644
index 6d98a3cd091..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch
+++ /dev/null
@@ -1,32 +0,0 @@
-From ebe5486739006105629b0bca6022f664566e56de Mon Sep 17 00:00:00 2001
-From: Sebastian Pipping <sebastian@pipping.org>
-Date: Sun, 8 Mar 2026 22:14:41 +0100
-Subject: [PATCH 5/7] lib: Extract a constant for upcoming reuse
-
-(cherry picked from commit fb35f2d2040d114f355bae8a7450942533237530)
-
-CVE: CVE-2026-45186
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/fb35f2d2040d114f355bae8a7450942533237530]
-Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
----
- lib/xmlparse.c | 3 ++-
- 1 file changed, 2 insertions(+), 1 deletion(-)
-
-diff --git a/lib/xmlparse.c b/lib/xmlparse.c
-index 0248b66..e833520 100644
---- a/lib/xmlparse.c
-+++ b/lib/xmlparse.c
-@@ -7719,8 +7719,9 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
- newE->prefix = (PREFIX *)lookup(oldParser, &(newDtd->prefixes),
- oldE->prefix->name, 0);
- for (i = 0; i < newE->nDefaultAtts; i++) {
-+ const XML_Char *const attributeName = oldE->defaultAtts[i].id->name;
- newE->defaultAtts[i].id = (ATTRIBUTE_ID *)lookup(
-- oldParser, &(newDtd->attributeIds), oldE->defaultAtts[i].id->name, 0);
-+ oldParser, &(newDtd->attributeIds), attributeName, 0);
- newE->defaultAtts[i].isCdata = oldE->defaultAtts[i].isCdata;
- if (oldE->defaultAtts[i].value) {
- newE->defaultAtts[i].value
---
-2.43.0
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch
deleted file mode 100644
index 1b47776a172..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch
+++ /dev/null
@@ -1,87 +0,0 @@
-From 41f9f3c8479e8f8547d5bce6355b0484c2744d1e Mon Sep 17 00:00:00 2001
-From: Sebastian Pipping <sebastian@pipping.org>
-Date: Sun, 8 Mar 2026 23:05:49 +0100
-Subject: [PATCH 6/7] lib: Introduce ELEMENT_TYPE.defaultAttsNames
-
-(cherry picked from commit 7f0f1b9e70d937072d2e9e37ae9edf27784cc080)
-
-CVE: CVE-2026-45186
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/7f0f1b9e70d937072d2e9e37ae9edf27784cc080]
-Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
----
- lib/xmlparse.c | 17 +++++++++++++++++
- 1 file changed, 17 insertions(+)
-
-diff --git a/lib/xmlparse.c b/lib/xmlparse.c
-index e833520..b7e2d72 100644
---- a/lib/xmlparse.c
-+++ b/lib/xmlparse.c
-@@ -388,6 +388,7 @@ typedef struct {
- int nDefaultAtts;
- int allocDefaultAtts;
- DEFAULT_ATTRIBUTE *defaultAtts;
-+ HASH_TABLE defaultAttsNames;
- } ELEMENT_TYPE;
-
- typedef struct {
-@@ -3853,6 +3854,8 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr,
- sizeof(ELEMENT_TYPE));
- if (! elementType)
- return XML_ERROR_NO_MEMORY;
-+ if (! elementType->defaultAttsNames.parser)
-+ hashTableInit(&(elementType->defaultAttsNames), parser);
- if (parser->m_ns && ! setElementTypePrefix(parser, elementType))
- return XML_ERROR_NO_MEMORY;
- }
-@@ -7561,6 +7564,7 @@ dtdReset(DTD *p, XML_Parser parser) {
- ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter);
- if (! e)
- break;
-+ hashTableDestroy(&(e->defaultAttsNames));
- if (e->allocDefaultAtts != 0)
- FREE(parser, e->defaultAtts);
- }
-@@ -7602,6 +7606,7 @@ dtdDestroy(DTD *p, XML_Bool isDocEntity, XML_Parser parser) {
- ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter);
- if (! e)
- break;
-+ hashTableDestroy(&(e->defaultAttsNames));
- if (e->allocDefaultAtts != 0)
- FREE(parser, e->defaultAtts);
- }
-@@ -7695,6 +7700,10 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
- sizeof(ELEMENT_TYPE));
- if (! newE)
- return 0;
-+
-+ if (! newE->defaultAttsNames.parser)
-+ hashTableInit(&(newE->defaultAttsNames), parser);
-+
- if (oldE->nDefaultAtts) {
- /* Detect and prevent integer overflow.
- * The preprocessor guard addresses the "always false" warning
-@@ -7730,6 +7739,12 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
- return 0;
- } else
- newE->defaultAtts[i].value = NULL;
-+
-+ NAMED *const nameAddedOrFound = (NAMED *)lookup(
-+ parser, &(newE->defaultAttsNames), attributeName, sizeof(NAMED));
-+ if (! nameAddedOrFound) {
-+ return 0;
-+ }
- }
- }
-
-@@ -8474,6 +8489,8 @@ getElementType(XML_Parser parser, const ENCODING *enc, const char *ptr,
- sizeof(ELEMENT_TYPE));
- if (! ret)
- return NULL;
-+ if (! ret->defaultAttsNames.parser)
-+ hashTableInit(&(ret->defaultAttsNames), getRootParserOf(parser, NULL));
- if (ret->name != name)
- poolDiscard(&dtd->pool);
- else {
---
-2.43.0
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch
deleted file mode 100644
index 5551d10243c..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch
+++ /dev/null
@@ -1,52 +0,0 @@
-From 141a3c12639f9a4066293e81dbedde4c15b0881f Mon Sep 17 00:00:00 2001
-From: Sebastian Pipping <sebastian@pipping.org>
-Date: Sun, 8 Mar 2026 23:06:29 +0100
-Subject: [PATCH 7/7] lib: Leverage ELEMENT_TYPE.defaultAttsNames for attribute
- collision detection
-
-.. to resolve quadratic runtime behavior
-
-(cherry picked from commit 4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5)
-
-CVE: CVE-2026-45186
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5]
-Signed-off-by: Theo Gaige <tgaige.opensource@witekio.com>
----
- lib/xmlparse.c | 14 ++++++++++----
- 1 file changed, 10 insertions(+), 4 deletions(-)
-
-diff --git a/lib/xmlparse.c b/lib/xmlparse.c
-index b7e2d72..04195cb 100644
---- a/lib/xmlparse.c
-+++ b/lib/xmlparse.c
-@@ -7189,10 +7189,10 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata,
- if (value || isId) {
- /* The handling of default attributes gets messed up if we have
- a default which duplicates a non-default. */
-- int i;
-- for (i = 0; i < type->nDefaultAtts; i++)
-- if (attId == type->defaultAtts[i].id)
-- return 1;
-+ NAMED *const nameFound
-+ = (NAMED *)lookup(parser, &(type->defaultAttsNames), attId->name, 0);
-+ if (nameFound)
-+ return 1;
- if (isId && ! type->idAtt && ! attId->xmlns)
- type->idAtt = attId;
- }
-@@ -7239,6 +7239,12 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata,
- att->isCdata = isCdata;
- if (! isCdata)
- attId->maybeTokenized = XML_TRUE;
-+
-+ NAMED *const nameAddedOrFound = (NAMED *)lookup(
-+ parser, &(type->defaultAttsNames), attId->name, sizeof(NAMED));
-+ if (! nameAddedOrFound)
-+ return 0;
-+
- type->nDefaultAtts += 1;
- return 1;
- }
---
-2.43.0
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch
deleted file mode 100644
index a413bf0acd0..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch
+++ /dev/null
@@ -1,90 +0,0 @@
-From 2e5920edcbc77bf29ce8575bd38ed2886408f4af Mon Sep 17 00:00:00 2001
-From: Matthew Fernandez <matthew.fernandez@gmail.com>
-Date: Thu, 4 Jun 2026 17:01:02 -0700
-Subject: [PATCH] lib: Remove reuse of `m_groupSize` to count `m_scaffIndex`
- allocation
-
-The sizes of the two arrays `m_groupConnector` and `scaffIndex` need to
-vary independently. This change is a step towards allowing this.
-
-Anthropic: ANT-2026-00037
-Anthropic: ANT-2026-03621
-Anthropic: ANT-2026-03867
-Co-authored-by: Alessandro Gario <alessandro.gario@trailofbits.com>
-
-CVE: CVE-2026-56132
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/3a4eaf47af8fd7abda38ea2c08308c91152061f3]
-
-(cherry picked from commit 3a4eaf47af8fd7abda38ea2c08308c91152061f3)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 8 ++++++--
- 1 file changed, 6 insertions(+), 2 deletions(-)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index 8e90fea8..d4864af8 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -424,6 +424,7 @@ typedef struct {
- unsigned scaffCount;
- int scaffLevel;
- int *scaffIndex;
-+ size_t scaffIndexSize;
- } DTD;
-
- enum EntityType {
-@@ -5995,7 +5996,6 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
- * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
- #if UINT_MAX >= SIZE_MAX
- if (parser->m_groupSize > SIZE_MAX / sizeof(int)) {
-- parser->m_groupSize /= 2;
- return XML_ERROR_NO_MEMORY;
- }
- #endif
-@@ -6003,10 +6003,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
- int *const new_scaff_index = REALLOC(
- parser, dtd->scaffIndex, parser->m_groupSize * sizeof(int));
- if (new_scaff_index == NULL) {
-- parser->m_groupSize /= 2;
- return XML_ERROR_NO_MEMORY;
- }
- dtd->scaffIndex = new_scaff_index;
-+ dtd->scaffIndexSize = parser->m_groupSize;
- }
- } else {
- parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32);
-@@ -7587,6 +7587,7 @@ dtdCreate(XML_Parser parser) {
-
- p->in_eldecl = XML_FALSE;
- p->scaffIndex = NULL;
-+ p->scaffIndexSize = 0;
- p->scaffold = NULL;
- p->scaffLevel = 0;
- p->scaffSize = 0;
-@@ -7627,6 +7628,7 @@ dtdReset(DTD *p, XML_Parser parser) {
-
- FREE(parser, p->scaffIndex);
- p->scaffIndex = NULL;
-+ p->scaffIndexSize = 0;
- FREE(parser, p->scaffold);
- p->scaffold = NULL;
-
-@@ -7801,6 +7803,7 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
- newDtd->scaffSize = oldDtd->scaffSize;
- newDtd->scaffLevel = oldDtd->scaffLevel;
- newDtd->scaffIndex = oldDtd->scaffIndex;
-+ newDtd->scaffIndexSize = oldDtd->scaffIndexSize;
-
- return 1;
- } /* End dtdCopy */
-@@ -8331,6 +8334,7 @@ nextScaffoldPart(XML_Parser parser) {
- dtd->scaffIndex = MALLOC(parser, parser->m_groupSize * sizeof(int));
- if (! dtd->scaffIndex)
- return -1;
-+ dtd->scaffIndexSize = parser->m_groupSize;
- dtd->scaffIndex[0] = 0;
- }
-
---
-2.43.7
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch
deleted file mode 100644
index 6fb8f6078ba..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch
+++ /dev/null
@@ -1,63 +0,0 @@
-From 2b6ebe08e4b6b3dd4d0f4f197dac18eecef16e6e Mon Sep 17 00:00:00 2001
-From: Matthew Fernandez <matthew.fernandez@gmail.com>
-Date: Thu, 4 Jun 2026 17:01:02 -0700
-Subject: [PATCH] lib: doProlog: Fix out-of-bound scaffolding index store
-MIME-Version: 1.0
-Content-Type: text/plain; charset=UTF-8
-Content-Transfer-Encoding: 8bit
-
-The scaffold backing array is reallocated using the caller parser’s
-per-parser `m_groupSize`, but the DTD struct (which carries
-`scaffIndex`) is shared between a parent parser and any external
-parameter-entity sub-parser created via
-`XML_ExternalEntityParserCreate(parent, NULL, …)`. A sub-parser whose
-group nesting is shallower than the parent’s can `REALLOC` the shared
-`scaffIndex` down to its own size; when the parent resumes and parses a
-deeper element content model, its bounds check passes (its private
-`m_groupSize` is still large enough), the doubling-grow path is skipped,
-and the next write lands past the shrunken buffer.
-
-Anthropic: ANT-2026-00037
-Anthropic: ANT-2026-03621
-Anthropic: ANT-2026-03867
-Co-authored-by: Alessandro Gario <alessandro.gario@trailofbits.com>
-Reported-by: Trail of Bits, in collaboration with Anthropic
-
-CVE: CVE-2026-56132
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/58400483d7c97be316d7a77739c0a6af5d55932e]
-
-(cherry picked from commit 58400483d7c97be316d7a77739c0a6af5d55932e)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 15 +++++++++++++++
- 1 file changed, 15 insertions(+)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index d4864af8..b528c9bc 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -6022,6 +6022,21 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
- if (myindex < 0)
- return XML_ERROR_NO_MEMORY;
- assert(dtd->scaffIndex != NULL);
-+ if ((size_t)dtd->scaffLevel >= dtd->scaffIndexSize) {
-+ /* Detect and prevent integer overflow */
-+ if (dtd->scaffIndexSize > SIZE_MAX / 2 / sizeof(int)) {
-+ return XML_ERROR_NO_MEMORY;
-+ }
-+ assert(dtd->scaffIndexSize > 0);
-+ const size_t new_size = dtd->scaffIndexSize * 2;
-+ int *const new_scaff_index
-+ = REALLOC(parser, dtd->scaffIndex, new_size * sizeof(int));
-+ if (new_scaff_index == NULL) {
-+ return XML_ERROR_NO_MEMORY;
-+ }
-+ dtd->scaffIndex = new_scaff_index;
-+ dtd->scaffIndexSize = new_size;
-+ }
- dtd->scaffIndex[dtd->scaffLevel] = myindex;
- dtd->scaffLevel++;
- dtd->scaffold[myindex].type = XML_CTYPE_SEQ;
---
-2.43.7
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch
deleted file mode 100644
index 5405224ec38..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch
+++ /dev/null
@@ -1,77 +0,0 @@
-From 22805ecc87ba8f66b693220442408a6f7c7e741d Mon Sep 17 00:00:00 2001
-From: Matthew Fernandez <matthew.fernandez@gmail.com>
-Date: Thu, 4 Jun 2026 17:01:02 -0700
-Subject: [PATCH] tests: Add a test case for scaffolding array limits in shared
- DTDs
-
-This test case provokes the bug fixed in the previous commit.
-
-Anthropic: ANT-2026-00037
-Anthropic: ANT-2026-03621
-Anthropic: ANT-2026-03867
-Co-authored-by: Alessandro Gario <alessandro.gario@trailofbits.com>
-Reported-by: Trail of Bits, in collaboration with Anthropic
-
-CVE: CVE-2026-56132
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/353919b3b9f2174073a557ac7d517a5f3cd0cbbf]
-
-(cherry picked from commit 353919b3b9f2174073a557ac7d517a5f3cd0cbbf)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/tests/basic_tests.c | 33 +++++++++++++++++++++++++++++++++
- 1 file changed, 33 insertions(+)
-
-diff --git a/expat/tests/basic_tests.c b/expat/tests/basic_tests.c
-index 02d1d5fd..53b920da 100644
---- a/expat/tests/basic_tests.c
-+++ b/expat/tests/basic_tests.c
-@@ -4091,6 +4091,37 @@ START_TEST(test_skipped_external_entity) {
- }
- END_TEST
-
-+START_TEST(test_scaff_index_shared_across_external_entity_parser) {
-+ const char text[]
-+ = "<!DOCTYPE doc [\n"
-+ "<!ELEMENT a "
-+ "((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((b))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))>\n"
-+ "<!ENTITY % e SYSTEM 'ext'>\n"
-+ "%e;\n"
-+ "<!ELEMENT c "
-+ "(((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((d)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))>\n"
-+ "]>\n"
-+ "<doc/>";
-+ ExtOption options[]
-+ = {{XCS("ext"),
-+ "<!ELEMENT x "
-+ "((((((((((((((((((((((((((((((((y))))))))))))))))))))))))))))))))>"},
-+ {NULL, NULL}};
-+
-+ XML_Parser parser = XML_ParserCreate(NULL);
-+ XML_SetParamEntityParsing(parser, XML_PARAM_ENTITY_PARSING_ALWAYS);
-+ XML_SetUserData(parser, options);
-+ XML_SetExternalEntityRefHandler(parser, external_entity_optioner);
-+ XML_SetElementDeclHandler(parser, dummy_element_decl_handler);
-+
-+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
-+ == XML_STATUS_ERROR)
-+ xml_failure(parser);
-+
-+ XML_ParserFree(parser);
-+}
-+END_TEST
-+
- /* Test a different form of unknown external entity */
- START_TEST(test_skipped_null_loaded_ext_entity) {
- const char *text = "<!DOCTYPE doc SYSTEM 'http://example.org/one.ent'>\n"
-@@ -6448,6 +6479,8 @@ make_basic_test_case(Suite *s) {
- tcase_add_test(tc_basic, test_trailing_cr_in_att_value);
- tcase_add_test(tc_basic, test_standalone_internal_entity);
- tcase_add_test(tc_basic, test_skipped_external_entity);
-+ tcase_add_test__ifdef_xml_dtd(
-+ tc_basic, test_scaff_index_shared_across_external_entity_parser);
- tcase_add_test(tc_basic, test_skipped_null_loaded_ext_entity);
- tcase_add_test(tc_basic, test_skipped_unloaded_ext_entity);
- tcase_add_test__ifdef_xml_dtd(tc_basic, test_param_entity_with_trailing_cr);
---
-2.43.7
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch
deleted file mode 100644
index 0cef4df4527..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch
+++ /dev/null
@@ -1,63 +0,0 @@
-From 36df125531dab7e0dc640b341d07b4b1f5ede37b Mon Sep 17 00:00:00 2001
-From: Matthew Fernandez <matthew.fernandez@gmail.com>
-Date: Thu, 4 Jun 2026 17:01:02 -0700
-Subject: [PATCH] lib: Remove unnecessary `scaffIndex` expansion
-
-Following the previous changes, all locations that append entries to
-`scaffIndex` handle expanding the array if it is not already large
-enough. So this extra expansion code is no longer necessary. In some
-cases such as processing siblings with alternating scaffolding counts,
-this logic would actually _shrink_ the array only to then later
-re-expand it.
-
-Anthropic: ANT-2026-00037
-Anthropic: ANT-2026-03621
-Anthropic: ANT-2026-03867
-Co-authored-by: Alessandro Gario <alessandro.gario@trailofbits.com>
-
-CVE: CVE-2026-56132
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/bca93b4ba9e15fd84425568d772b69baebf790e4]
-
-Backport Changes:
-- Remove the expanded Expat 2.7.5 scaffIndex resize block, including its
- branch-specific integer overflow guard.
-
-(cherry picked from commit bca93b4ba9e15fd84425568d772b69baebf790e4)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 20 --------------------
- 1 file changed, 20 deletions(-)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index b528c9bc..e59ad556 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -5988,26 +5988,6 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
- }
- parser->m_groupConnector = new_connector;
- }
--
-- if (dtd->scaffIndex) {
-- /* Detect and prevent integer overflow.
-- * The preprocessor guard addresses the "always false" warning
-- * from -Wtype-limits on platforms where
-- * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
--#if UINT_MAX >= SIZE_MAX
-- if (parser->m_groupSize > SIZE_MAX / sizeof(int)) {
-- return XML_ERROR_NO_MEMORY;
-- }
--#endif
--
-- int *const new_scaff_index = REALLOC(
-- parser, dtd->scaffIndex, parser->m_groupSize * sizeof(int));
-- if (new_scaff_index == NULL) {
-- return XML_ERROR_NO_MEMORY;
-- }
-- dtd->scaffIndex = new_scaff_index;
-- dtd->scaffIndexSize = parser->m_groupSize;
-- }
- } else {
- parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32);
- if (! parser->m_groupConnector) {
---
-2.43.7
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch
deleted file mode 100644
index 8655298b65f..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch
+++ /dev/null
@@ -1,58 +0,0 @@
-From c6256eca63fe36d4ef26fd59cbcaab7b72e1d6f2 Mon Sep 17 00:00:00 2001
-From: Matthew Fernandez <matthew.fernandez@gmail.com>
-Date: Thu, 4 Jun 2026 17:01:02 -0700
-Subject: [PATCH] lib: Remove indented scoping of `new_connector` local
-
-Following the previous change, the lifetime of `new_connector` as
-constrained by this introduced scope was identical to the parent scope.
-
-CVE: CVE-2026-56132
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/08baa7ef9d168b99094249998fd78f8d190526e5]
-
-Backport Changes:
-- Keep the Expat 2.7.5 unsigned-int overflow guard while removing the
- redundant new_connector scope.
-
-(cherry picked from commit 08baa7ef9d168b99094249998fd78f8d190526e5)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 22 ++++++++++------------
- 1 file changed, 10 insertions(+), 12 deletions(-)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index e59ad556..e8d6fc3a 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -5974,20 +5974,18 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
- case XML_ROLE_GROUP_OPEN:
- if (parser->m_prologState.level >= parser->m_groupSize) {
- if (parser->m_groupSize) {
-- {
-- /* Detect and prevent integer overflow */
-- if (parser->m_groupSize > (unsigned int)(-1) / 2u) {
-- return XML_ERROR_NO_MEMORY;
-- }
-+ /* Detect and prevent integer overflow */
-+ if (parser->m_groupSize > (unsigned int)(-1) / 2u) {
-+ return XML_ERROR_NO_MEMORY;
-+ }
-
-- char *const new_connector = REALLOC(
-- parser, parser->m_groupConnector, parser->m_groupSize *= 2);
-- if (new_connector == NULL) {
-- parser->m_groupSize /= 2;
-- return XML_ERROR_NO_MEMORY;
-- }
-- parser->m_groupConnector = new_connector;
-+ char *const new_connector = REALLOC(parser, parser->m_groupConnector,
-+ parser->m_groupSize *= 2);
-+ if (new_connector == NULL) {
-+ parser->m_groupSize /= 2;
-+ return XML_ERROR_NO_MEMORY;
- }
-+ parser->m_groupConnector = new_connector;
- } else {
- parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32);
- if (! parser->m_groupConnector) {
---
-2.43.7
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch
deleted file mode 100644
index 4cf5c3bd54d..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch
+++ /dev/null
@@ -1,83 +0,0 @@
-From 4a264be1794368a1acc08476058b6cf087686d11 Mon Sep 17 00:00:00 2001
-From: Sebastian Pipping <sebastian@pipping.org>
-Date: Wed, 20 May 2026 12:12:10 +0200
-Subject: [PATCH] lib: Protect function `storeAtts` from signed integer
- overflow
-
-CVE: CVE-2026-56403
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648]
-
-Backport Changes:
-- Retain the Expat 2.7.5 binding URI reallocation and active tag pointer
- updates while using the overflow-safe localPartLen calculation.
-
-(cherry picked from commit 12dc6d8d3d65f79471a94d8565f6bf1cf245f648)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 30 ++++++++++++++++++++----------
- 1 file changed, 20 insertions(+), 10 deletions(-)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index 0248b665..e441ff7f 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -4235,26 +4235,32 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr,
- return XML_ERROR_NONE;
- prefixLen = 0;
- if (parser->m_ns_triplets && binding->prefix->name) {
-- while (binding->prefix->name[prefixLen++])
-- ; /* prefixLen includes null terminator */
-+ size_t candidateLen = 0;
-+ while (binding->prefix->name[candidateLen++])
-+ ; /* candidateLen includes null terminator */
-+ /* Detect and prevent integer overflow */
-+ if (candidateLen > INT_MAX)
-+ return XML_ERROR_NO_MEMORY;
-+ prefixLen = (int)candidateLen;
- }
- tagNamePtr->localPart = localPart;
- tagNamePtr->uriLen = binding->uriLen;
- tagNamePtr->prefix = binding->prefix->name;
- tagNamePtr->prefixLen = prefixLen;
-- for (i = 0; localPart[i++];)
-- ; /* i includes null terminator */
-+
-+ size_t localPartLen = 0;
-+ for (; localPart[localPartLen++];)
-+ ; /* localPartLen includes null terminator */
-
- /* Detect and prevent integer overflow */
-- if (binding->uriLen > INT_MAX - prefixLen
-- || i > INT_MAX - (binding->uriLen + prefixLen)) {
-+ if (localPartLen > INT_MAX || binding->uriLen > INT_MAX - prefixLen
-+ || localPartLen > (size_t)INT_MAX - (binding->uriLen + prefixLen)) {
- return XML_ERROR_NO_MEMORY;
- }
-
-- n = i + binding->uriLen + prefixLen;
-+ n = (int)localPartLen + binding->uriLen + prefixLen;
- if (n > binding->uriAlloc) {
- TAG *p;
--
- /* Detect and prevent integer overflow */
- if (n > INT_MAX - EXPAND_SPARE) {
- return XML_ERROR_NO_MEMORY;
-@@ -4282,10 +4288,14 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr,
- }
- /* if m_namespaceSeparator != '\0' then uri includes it already */
- uri = binding->uri + binding->uriLen;
-- memcpy(uri, localPart, i * sizeof(XML_Char));
-+ /* Detect and prevent integer overflow */
-+ if (localPartLen > SIZE_MAX / sizeof(XML_Char)) {
-+ return XML_ERROR_NO_MEMORY;
-+ }
-+ memcpy(uri, localPart, localPartLen * sizeof(XML_Char));
- /* we always have a namespace separator between localPart and prefix */
- if (prefixLen) {
-- uri += i - 1;
-+ uri += localPartLen - 1;
- *uri = parser->m_namespaceSeparator; /* replace null terminator */
- memcpy(uri + 1, binding->prefix->name, prefixLen * sizeof(XML_Char));
- }
---
-2.43.7
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch
deleted file mode 100644
index 62fdff79e3c..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch
+++ /dev/null
@@ -1,40 +0,0 @@
-From e8100827a4f68c70d8cadf446bb82bec7cbebbac Mon Sep 17 00:00:00 2001
-From: Sebastian Pipping <sebastian@pipping.org>
-Date: Fri, 22 May 2026 00:43:52 +0200
-Subject: [PATCH] xmlwf: Protect function `xcsdup` from signed integer overflow
-
-CVE: CVE-2026-56403
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/147c8f36d6277d5c6011c098370a8362aed47b15]
-
-(cherry picked from commit 147c8f36d6277d5c6011c098370a8362aed47b15)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/xmlwf/xmlwf.c | 7 ++++++-
- 1 file changed, 6 insertions(+), 1 deletion(-)
-
-diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c
-index 2d0c4f8e..934473ce 100644
---- a/expat/xmlwf/xmlwf.c
-+++ b/expat/xmlwf/xmlwf.c
-@@ -305,13 +305,18 @@ processingInstruction(void *userData, const XML_Char *target,
- static XML_Char *
- xcsdup(const XML_Char *s) {
- XML_Char *result;
-- int count = 0;
-+ size_t count = 0;
- size_t numBytes;
-
- /* Get the length of the string, including terminator */
- while (s[count++] != 0) {
- /* Do nothing */
- }
-+
-+ // Detect and prevent integer overflow
-+ if (count > SIZE_MAX / sizeof(XML_Char))
-+ return NULL;
-+
- numBytes = count * sizeof(XML_Char);
- result = malloc(numBytes);
- if (result == NULL)
---
-2.43.7
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56404.patch b/meta/recipes-core/expat/expat/CVE-2026-56404.patch
deleted file mode 100644
index 6bca7cf961c..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56404.patch
+++ /dev/null
@@ -1,47 +0,0 @@
-From 8cb4583ac3204175a03c8ea8e371adee583b0bec Mon Sep 17 00:00:00 2001
-From: netliomax25-code <netliomax25@gmail.com>
-Date: Thu, 28 May 2026 12:44:11 +0530
-Subject: [PATCH] lib: protect function addBinding from signed integer overflow
-
-CVE: CVE-2026-56404
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164]
-
-(cherry picked from commit babfc48090977cbf7be24b2c48f6053dca75c164)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 11 ++++++++++-
- 1 file changed, 10 insertions(+), 1 deletion(-)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index 53f842d1..33b92c9c 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -4485,6 +4485,10 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId,
- }
-
- for (len = 0; uri[len]; len++) {
-+ /* Detect and prevent signed integer overflow */
-+ if (len == INT_MAX) {
-+ return XML_ERROR_NO_MEMORY;
-+ }
- if (isXML && (len > xmlLen || uri[len] != xmlNamespace[len]))
- isXML = XML_FALSE;
-
-@@ -4525,8 +4529,13 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId,
- if (isXMLNS)
- return XML_ERROR_RESERVED_NAMESPACE_URI;
-
-- if (parser->m_namespaceSeparator)
-+ if (parser->m_namespaceSeparator) {
-+ /* Detect and prevent signed integer overflow */
-+ if (len == INT_MAX) {
-+ return XML_ERROR_NO_MEMORY;
-+ }
- len++;
-+ }
- if (parser->m_freeBindingList) {
- b = parser->m_freeBindingList;
- if (len > b->uriAlloc) {
---
-2.43.7
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56405.patch b/meta/recipes-core/expat/expat/CVE-2026-56405.patch
deleted file mode 100644
index c850801c1ac..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56405.patch
+++ /dev/null
@@ -1,32 +0,0 @@
-From 73209f445f0265b203829fa7873caa78ca83cefe Mon Sep 17 00:00:00 2001
-From: netliomax25-code <netliomax25@gmail.com>
-Date: Fri, 29 May 2026 11:45:17 +0530
-Subject: [PATCH] lib: Protect function getAttributeId from signed integer
- overflow
-
-CVE: CVE-2026-56405
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0]
-
-(cherry picked from commit 2c6c42d33689f6b266a5267b639e03cde17e53c0)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 4 ++++
- 1 file changed, 4 insertions(+)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index 1b7e289f..ec707336 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -7324,6 +7324,10 @@ getAttributeId(XML_Parser parser, const ENCODING *enc, const char *start,
- } else {
- int i;
- for (i = 0; name[i]; i++) {
-+ /* Detect and prevent signed integer overflow */
-+ if (i == INT_MAX) {
-+ return NULL;
-+ }
- /* attributes without prefix are *not* in the default namespace */
- if (name[i] == XML_T(ASCII_COLON)) {
- int j;
---
-2.43.7
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch b/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch
deleted file mode 100644
index 6ef7c42298c..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch
+++ /dev/null
@@ -1,58 +0,0 @@
-From 4f828b7ee9d6efef618e8a99a0392acbb95e84f2 Mon Sep 17 00:00:00 2001
-From: Matthew Fernandez <matthew.fernandez@gmail.com>
-Date: Wed, 27 May 2026 17:01:44 -0700
-Subject: [PATCH] lib: Make `XML_Index` overflow check more intuitive
-
-In fixing a bug, 7e5b71b748491b6e459e5c9a1d090820f94544d8 introduced a
-magic number `2` in this code that made it difficult to understand the
-rationale for this overflow check without reading the commit log. This
-change introduces some more readable constants to use in these
-situations.
-
-CVE: CVE-2026-56406
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/252ff1a307b1490ce0f430632791e7e52d7e43fd]
-
-(cherry picked from commit 252ff1a307b1490ce0f430632791e7e52d7e43fd)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 10 ++++++++--
- 1 file changed, 8 insertions(+), 2 deletions(-)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index 96127bf8..5ecea7a8 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -101,7 +101,7 @@
- #include <stddef.h>
- #include <string.h> /* memset(), memcpy() */
- #include <assert.h>
--#include <limits.h> /* INT_MAX, UINT_MAX */
-+#include <limits.h> /* INT_MAX, LLONG_MAX, LONG_MAX, UINT_MAX */
- #include <stdio.h> /* fprintf */
- #include <stdlib.h> /* getenv, rand_s */
- #include <stdint.h> /* SIZE_MAX, uintptr_t */
-@@ -209,6 +209,12 @@ typedef char ICHAR;
-
- #endif
-
-+#ifdef XML_LARGE_SIZE
-+# define XML_INDEX_MAX LLONG_MAX
-+#else
-+# define XML_INDEX_MAX LONG_MAX
-+#endif
-+
- /* Round up n to be a multiple of sz, where sz is a power of 2. */
- #define ROUND_UP(n, sz) (((n) + ((sz) - 1)) & ~((sz) - 1))
-
-@@ -2395,7 +2401,7 @@ XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) {
- int nLeftOver;
- enum XML_Status result;
- /* Detect overflow (a+b > MAX <==> b > MAX-a) */
-- if ((XML_Size)len > ((XML_Size)-1) / 2 - parser->m_parseEndByteIndex) {
-+ if (len > XML_INDEX_MAX - parser->m_parseEndByteIndex) {
- parser->m_errorCode = XML_ERROR_NO_MEMORY;
- parser->m_eventPtr = parser->m_eventEndPtr = NULL;
- parser->m_processor = errorProcessor;
---
-2.43.7
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56406.patch b/meta/recipes-core/expat/expat/CVE-2026-56406.patch
deleted file mode 100644
index 4077b9946a9..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56406.patch
+++ /dev/null
@@ -1,37 +0,0 @@
-From 6e52f18aded0a76cf89f191d7810bc04287f5337 Mon Sep 17 00:00:00 2001
-From: Sebastian Pipping <sebastian@pipping.org>
-Date: Sun, 31 May 2026 15:18:58 +0200
-Subject: [PATCH] lib: Copy overflow check from `XML_Parse` to
- `XML_ParseBuffer`
-
-CVE: CVE-2026-56406
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d]
-
-(cherry picked from commit 99d8454fdf900a6d00c2a52748e6c0eeb507574d)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 8 ++++++++
- 1 file changed, 8 insertions(+)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index 5ecea7a8..71fe2c79 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -2518,6 +2518,14 @@ XML_ParseBuffer(XML_Parser parser, int len, int isFinal) {
- parser->m_parsingStatus.parsing = XML_PARSING;
- }
-
-+ // Detect and avoid integer overflow
-+ if (len > XML_INDEX_MAX - parser->m_parseEndByteIndex) {
-+ parser->m_errorCode = XML_ERROR_NO_MEMORY;
-+ parser->m_eventPtr = parser->m_eventEndPtr = NULL;
-+ parser->m_processor = errorProcessor;
-+ return XML_STATUS_ERROR;
-+ }
-+
- start = parser->m_bufferPtr;
- parser->m_positionPtr = start;
- parser->m_bufferEnd += len;
---
-2.43.7
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56407.patch b/meta/recipes-core/expat/expat/CVE-2026-56407.patch
deleted file mode 100644
index 5a2a22e0172..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56407.patch
+++ /dev/null
@@ -1,44 +0,0 @@
-From 7216b3584bcfb2d415026d16b8902ee7eacad5ca Mon Sep 17 00:00:00 2001
-From: netliomax25-code <netliomax25@gmail.com>
-Date: Tue, 2 Jun 2026 11:59:01 +0530
-Subject: [PATCH] cap entity textLen against signed integer overflow
-
-CVE: CVE-2026-56407
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13]
-
-(cherry picked from commit 30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 9 +++++++++
- 1 file changed, 9 insertions(+)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index 71fe2c79..8e90fea8 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -5684,6 +5684,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
- parser, enc, s + enc->minBytesPerChar, next - enc->minBytesPerChar,
- XML_ACCOUNT_NONE);
- if (parser->m_declEntity) {
-+ /* Detect and prevent signed integer overflow */
-+ if ((size_t)poolLength(&dtd->entityValuePool) > (size_t)INT_MAX) {
-+ return XML_ERROR_NO_MEMORY;
-+ }
- parser->m_declEntity->textPtr = poolStart(&dtd->entityValuePool);
- parser->m_declEntity->textLen
- = (int)(poolLength(&dtd->entityValuePool));
-@@ -7099,6 +7103,11 @@ storeSelfEntityValue(XML_Parser parser, ENTITY *entity) {
- return XML_ERROR_NO_MEMORY;
- }
-
-+ /* Detect and prevent signed integer overflow */
-+ if ((size_t)poolLength(pool) > (size_t)INT_MAX) {
-+ poolDiscard(pool);
-+ return XML_ERROR_NO_MEMORY;
-+ }
- entity->textPtr = poolStart(pool);
- entity->textLen = (int)(poolLength(pool));
- poolFinish(pool);
---
-2.43.7
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56408.patch b/meta/recipes-core/expat/expat/CVE-2026-56408.patch
deleted file mode 100644
index b8c43636cc0..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56408.patch
+++ /dev/null
@@ -1,36 +0,0 @@
-From b0cf9e9b0f5dfdd938148931a4605a0fd6b917a7 Mon Sep 17 00:00:00 2001
-From: Sebastian Pipping <sebastian@pipping.org>
-Date: Thu, 23 Apr 2026 10:31:45 +0200
-Subject: [PATCH] lib: Waterproof `copyString` from integer overflow
-
-CVE: CVE-2026-56408
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817]
-
-Backport Changes:
-- Adapt the fix to Expat 2.7.5, which calculates charsRequired using
- an existing loop instead of xcslen. The upstream string helper
- refactoring is not required for the overflow guard.
-
-(cherry picked from commit 16e2efd867ea8567ffa012210b52ef5918e20817)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/lib/xmlparse.c | 4 ++++
- 1 file changed, 4 insertions(+)
-
-diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
-index e441ff7f..4ff5e33b 100644
---- a/expat/lib/xmlparse.c
-+++ b/expat/lib/xmlparse.c
-@@ -8505,6 +8505,10 @@ copyString(const XML_Char *s, XML_Parser parser) {
- /* Include the terminator */
- charsRequired++;
-
-+ /* Detect and prevent integer overflow */
-+ if (charsRequired > SIZE_MAX / sizeof(XML_Char))
-+ return NULL;
-+
- /* Now allocate space for the copy */
- result = MALLOC(parser, charsRequired * sizeof(XML_Char));
- if (result == NULL)
---
-2.43.7
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56409.patch b/meta/recipes-core/expat/expat/CVE-2026-56409.patch
deleted file mode 100644
index ff0e650a2ab..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56409.patch
+++ /dev/null
@@ -1,53 +0,0 @@
-From 10938bc2cef7573087566b5b1c948061baa68b98 Mon Sep 17 00:00:00 2001
-From: netliomax25-code <netliomax25@gmail.com>
-Date: Mon, 1 Jun 2026 11:53:19 +0530
-Subject: [PATCH] xmlwf: protect output path join from integer overflow
-
-CVE: CVE-2026-56409
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e]
-
-Backport Changes:
-- Adapt the allocation hunk to the explicit cast used by Expat 2.7.5.
-
-(cherry picked from commit 61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/xmlwf/xmlwf.c | 22 ++++++++++++++++++++--
- 1 file changed, 20 insertions(+), 2 deletions(-)
-
-diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c
-index 06416454..6a0a707a 100644
---- a/expat/xmlwf/xmlwf.c
-+++ b/expat/xmlwf/xmlwf.c
-@@ -1236,8 +1236,26 @@ tmain(int argc, XML_Char **argv) {
- }
- #endif
- }
-- outName = (XML_Char *)malloc((tcslen(outputDir) + tcslen(file) + 2)
-- * sizeof(XML_Char));
-+ const size_t outputDirLen = tcslen(outputDir);
-+ const size_t fileLen = tcslen(file);
-+
-+ /* Detect and prevent integer overflow in the addition (without
-+ risking underflow) and the multiplication, mirroring the guards
-+ in xcsdup() and resolveSystemId() */
-+ if (outputDirLen > SIZE_MAX - fileLen
-+ || outputDirLen > SIZE_MAX - fileLen - 2) {
-+ tperror(T("Could not allocate memory"));
-+ exit(XMLWF_EXIT_INTERNAL_ERROR);
-+ }
-+
-+ const size_t charsRequired = outputDirLen + fileLen + 2;
-+
-+ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) {
-+ tperror(T("Could not allocate memory"));
-+ exit(XMLWF_EXIT_INTERNAL_ERROR);
-+ }
-+
-+ outName = malloc(charsRequired * sizeof(XML_Char));
- if (! outName) {
- tperror(T("Could not allocate memory"));
- exit(XMLWF_EXIT_INTERNAL_ERROR);
---
-2.43.7
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch
deleted file mode 100644
index aa4378f1b77..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch
+++ /dev/null
@@ -1,40 +0,0 @@
-From 759b77a8439bcbf57c86900bc472d46d8ef70c92 Mon Sep 17 00:00:00 2001
-From: netliomax25-code <netliomax25@gmail.com>
-Date: Fri, 29 May 2026 17:51:25 +0530
-Subject: [PATCH] xmlwf: protect resolveSystemId from integer overflow
-
-CVE: CVE-2026-56410
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347]
-
-Backport Changes:
-- Adjust the removed allocation line for Wrynose's explicit malloc cast while
- keeping upstream's overflow checks and final allocation logic.
-
-(cherry picked from commit deeb97f7c88d17a16b0ea2521a13733abc283347)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/xmlwf/xmlfile.c | 9 +++++++--
- 1 file changed, 7 insertions(+), 2 deletions(-)
-
-diff --git a/expat/xmlwf/xmlfile.c b/expat/xmlwf/xmlfile.c
-index c4eb839f..31a40209 100644
---- a/expat/xmlwf/xmlfile.c
-+++ b/expat/xmlwf/xmlfile.c
-@@ -138,8 +138,13 @@ resolveSystemId(const XML_Char *base, const XML_Char *systemId,
- #endif
- )
- return systemId;
-- *toFree = (XML_Char *)malloc((tcslen(base) + tcslen(systemId) + 2)
-- * sizeof(XML_Char));
-+ const size_t charsRequired = tcslen(base) + tcslen(systemId) + 2;
-+
-+ /* Detect and prevent integer overflow */
-+ if (charsRequired > SIZE_MAX / sizeof(XML_Char))
-+ return systemId;
-+
-+ *toFree = malloc(charsRequired * sizeof(XML_Char));
- if (! *toFree)
- return systemId;
- tcscpy(*toFree, base);
---
-2.43.7
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch
deleted file mode 100644
index 71f3122602a..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch
+++ /dev/null
@@ -1,41 +0,0 @@
-From f16fa442eaa81bfceec5302d977219959eaac7b7 Mon Sep 17 00:00:00 2001
-From: netliomax25-code <netliomax25@gmail.com>
-Date: Sat, 30 May 2026 11:28:51 +0530
-Subject: [PATCH] xmlwf: guard each operator in resolveSystemId length sum
-
-CVE: CVE-2026-56410
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea]
-
-(cherry picked from commit cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/xmlwf/xmlfile.c | 12 ++++++++++--
- 1 file changed, 10 insertions(+), 2 deletions(-)
-
-diff --git a/expat/xmlwf/xmlfile.c b/expat/xmlwf/xmlfile.c
-index 31a40209..15c69217 100644
---- a/expat/xmlwf/xmlfile.c
-+++ b/expat/xmlwf/xmlfile.c
-@@ -139,9 +139,17 @@ resolveSystemId(const XML_Char *base, const XML_Char *systemId,
- #endif
- )
- return systemId;
-- const size_t charsRequired = tcslen(base) + tcslen(systemId) + 2;
-+ const size_t baseLen = tcslen(base);
-+ const size_t systemIdLen = tcslen(systemId);
-
-- /* Detect and prevent integer overflow */
-+ /* Detect and prevent integer overflow in the addition (without risking
-+ underflow) */
-+ if (baseLen > SIZE_MAX - systemIdLen || baseLen > SIZE_MAX - systemIdLen - 2)
-+ return systemId;
-+
-+ const size_t charsRequired = baseLen + systemIdLen + 2;
-+
-+ /* Detect and prevent integer overflow in the multiplication */
- if (charsRequired > SIZE_MAX / sizeof(XML_Char))
- return systemId;
-
---
-2.43.7
-
diff --git a/meta/recipes-core/expat/expat/CVE-2026-56411.patch b/meta/recipes-core/expat/expat/CVE-2026-56411.patch
deleted file mode 100644
index 884837b61e1..00000000000
--- a/meta/recipes-core/expat/expat/CVE-2026-56411.patch
+++ /dev/null
@@ -1,47 +0,0 @@
-From e447d5d72884a1246894f111a5b72de4e479152e Mon Sep 17 00:00:00 2001
-From: netliomax25-code <netliomax25@gmail.com>
-Date: Tue, 2 Jun 2026 13:13:34 +0530
-Subject: [PATCH] xmlwf: protect notation list allocation from integer overflow
-
-CVE: CVE-2026-56411
-Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5]
-
-(cherry picked from commit 528a4e5017e1bd3b48b689fd0c131df940ae3ea5)
-Signed-off-by: Deepak Rathore <deeratho@cisco.com>
----
- expat/xmlwf/xmlwf.c | 11 +++++++++--
- 1 file changed, 9 insertions(+), 2 deletions(-)
-
-diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c
-index 6a0a707a..a9640190 100644
---- a/expat/xmlwf/xmlwf.c
-+++ b/expat/xmlwf/xmlwf.c
-@@ -383,9 +383,9 @@ static void XMLCALL
- endDoctypeDecl(void *userData) {
- XmlwfUserData *data = (XmlwfUserData *)userData;
- NotationList **notations;
-- int notationCount = 0;
-+ size_t notationCount = 0;
- NotationList *p;
-- int i;
-+ size_t i;
-
- /* How many notations do we have? */
- for (p = data->notationListHead; p != NULL; p = p->next)
-@@ -395,6 +395,13 @@ endDoctypeDecl(void *userData) {
- goto cleanUp;
- }
-
-+ /* Detect and prevent integer overflow in the multiplication, mirroring
-+ the guards in xcsdup() and resolveSystemId() */
-+ if (notationCount > SIZE_MAX / sizeof(NotationList *)) {
-+ fprintf(stderr, "Unable to sort notations");
-+ goto cleanUp;
-+ }
-+
- notations = malloc(notationCount * sizeof(NotationList *));
- if (notations == NULL) {
- fprintf(stderr, "Unable to sort notations");
---
-2.43.7
-
diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb
deleted file mode 100644
index da35b8f9ff5..00000000000
--- a/meta/recipes-core/expat/expat_2.7.5.bb
+++ /dev/null
@@ -1,62 +0,0 @@
-SUMMARY = "A stream-oriented XML parser library"
-DESCRIPTION = "Expat is an XML parser library written in C. It is a stream-oriented parser in which an application registers handlers for things the parser might find in the XML document (like start tags)"
-HOMEPAGE = "https://github.com/libexpat/libexpat"
-SECTION = "libs"
-LICENSE = "MIT"
-
-LIC_FILES_CHKSUM = "file://COPYING;md5=f4fedd6116da0e171f7cb4d2923d7ac2"
-
-VERSION_TAG = "${@d.getVar('PV').replace('.', '_')}"
-
-SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \
- file://run-ptest \
- file://CVE-2026-45186-01.patch \
- file://CVE-2026-45186-02.patch \
- file://CVE-2026-45186-03.patch \
- file://CVE-2026-45186-04.patch \
- file://CVE-2026-45186-05.patch \
- file://CVE-2026-45186-06.patch \
- file://CVE-2026-45186-07.patch \
- file://CVE-2026-41080-1.patch \
- file://CVE-2026-41080-2.patch \
- file://CVE-2026-56403_p1.patch;striplevel=2 \
- file://CVE-2026-56403_p2.patch;striplevel=2 \
- file://CVE-2026-56408.patch;striplevel=2 \
- file://CVE-2026-56404.patch;striplevel=2 \
- file://CVE-2026-56405.patch;striplevel=2 \
- file://CVE-2026-56410_p1.patch;striplevel=2 \
- file://CVE-2026-56410_p2.patch;striplevel=2 \
- file://CVE-2026-56406-dependent.patch;striplevel=2 \
- file://CVE-2026-56406.patch;striplevel=2 \
- file://CVE-2026-56409.patch;striplevel=2 \
- file://CVE-2026-56411.patch;striplevel=2 \
- file://CVE-2026-56407.patch;striplevel=2 \
- file://CVE-2026-56132_p1.patch;striplevel=2 \
- file://CVE-2026-56132_p2.patch;striplevel=2 \
- file://CVE-2026-56132_p3.patch;striplevel=2 \
- file://CVE-2026-56132_p4.patch;striplevel=2 \
- file://CVE-2026-56132_p5.patch;striplevel=2 \
- "
-
-GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"
-UPSTREAM_CHECK_REGEX = "releases/tag/R_(?P<pver>.+)"
-
-SRC_URI[sha256sum] = "386a423d40580f1e392e8b512b7635cac5083fe0631961e74e036b0a7a830d77"
-
-EXTRA_OECMAKE:class-native += "-DEXPAT_BUILD_DOCS=OFF"
-
-RDEPENDS:${PN}-ptest += "bash"
-
-inherit cmake lib_package ptest github-releases
-
-do_install_ptest:class-target() {
- install -m 755 ${B}/tests/runtests* ${D}${PTEST_PATH}
- install -m 755 ${B}/tests/benchmark/benchmark ${D}${PTEST_PATH}
-}
-
-BBCLASSEXTEND += "native nativesdk"
-
-CVE_PRODUCT = "expat libexpat"
-
-CVE_STATUS[CVE-2026-72522] = "not-applicable-config: Needs Expat compiled with 16bit character support , Issue only affects firefox/Windows. \
-EXPAT_CHAR_TYPE:STRING=char is for Yocto builds"
diff --git a/meta/recipes-core/expat/expat_2.8.3.bb b/meta/recipes-core/expat/expat_2.8.3.bb
new file mode 100644
index 00000000000..79e8c15227a
--- /dev/null
+++ b/meta/recipes-core/expat/expat_2.8.3.bb
@@ -0,0 +1,33 @@
+SUMMARY = "A stream-oriented XML parser library"
+DESCRIPTION = "Expat is an XML parser library written in C. It is a stream-oriented parser in which an application registers handlers for things the parser might find in the XML document (like start tags)"
+HOMEPAGE = "https://github.com/libexpat/libexpat"
+SECTION = "libs"
+LICENSE = "MIT"
+
+LIC_FILES_CHKSUM = "file://COPYING;md5=f4fedd6116da0e171f7cb4d2923d7ac2"
+
+VERSION_TAG = "${@d.getVar('PV').replace('.', '_')}"
+
+SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \
+ file://run-ptest \
+ "
+
+GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"
+UPSTREAM_CHECK_REGEX = "releases/tag/R_(?P<pver>.+)"
+
+SRC_URI[sha256sum] = "b4cc2483927d5e90bf8c40b44a6b95b368b42a8a96e25883fce188b48a92b670"
+
+EXTRA_OECMAKE:class-native += "-DEXPAT_BUILD_DOCS=OFF"
+
+RDEPENDS:${PN}-ptest += "bash"
+
+inherit cmake lib_package ptest github-releases
+
+do_install_ptest:class-target() {
+ install -m 755 ${B}/tests/runtests* ${D}${PTEST_PATH}
+ install -m 755 ${B}/tests/benchmark/benchmark ${D}${PTEST_PATH}
+}
+
+BBCLASSEXTEND += "native nativesdk"
+
+CVE_PRODUCT = "expat libexpat"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 51/79] curl: patch CVE-2026-7009
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (49 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 50/79] expat: upgrade 2.7.5 -> 2.8.3 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 52/79] curl: patch CVE-2026-8925 Yoann Congal
` (27 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Pick patch per [1].
[1] https://curl.se/docs/CVE-2026-7009.html
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../curl/curl/CVE-2026-7009.patch | 50 +++++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
2 files changed, 51 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-7009.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-7009.patch b/meta/recipes-support/curl/curl/CVE-2026-7009.patch
new file mode 100644
index 00000000000..ec124378eca
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-7009.patch
@@ -0,0 +1,50 @@
+From 51905671e07f087e28e5741063646c379fe17d89 Mon Sep 17 00:00:00 2001
+From: Stefan Eissing <stefan@eissing.org>
+Date: Sat, 25 Apr 2026 10:34:06 +0200
+Subject: [PATCH] sectrust: fail on missing OCSP stapling
+
+When using Apple SecTrust, requiring the server to send
+an OCSP response and does not, fail correctly.
+
+Reported-by: Carlos Carrillo
+Closes #21444
+
+CVE: CVE-2026-7009
+Upstream-Status: Backport [https://github.com/curl/curl/commit/51905671e07f087e28e5741063646c379fe17d89]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/vtls/openssl.c | 12 +++++++++++-
+ 1 file changed, 11 insertions(+), 1 deletion(-)
+
+diff --git a/lib/vtls/openssl.c b/lib/vtls/openssl.c
+index c84ef8bc65..4629ca4444 100644
+--- a/lib/vtls/openssl.c
++++ b/lib/vtls/openssl.c
+@@ -4744,16 +4744,26 @@ static CURLcode ossl_apple_verify(struct Curl_cfilter *cf,
+ unsigned char *ocsp_data = NULL;
+ #endif
+ long ocsp_len = 0;
++ bool ocsp_missing = FALSE;
+ if(conn_config->verifystatus && !octx->reused_session)
+ ocsp_len = (long)SSL_get_tlsext_status_ocsp_resp(octx->ssl, &ocsp_data);
+
+ /* SSL_get_tlsext_status_ocsp_resp() returns the length of the OCSP
+ response data or -1 if there is no OCSP response data. */
+- if(ocsp_len < 0)
++ if(ocsp_len < 0) {
+ ocsp_len = 0; /* no data available */
++ ocsp_missing = TRUE;
++ }
+ result = Curl_vtls_apple_verify(cf, data, peer, chain.num_certs,
+ ossl_chain_get_der, &chain,
+ ocsp_data, ocsp_len);
++ if(!result && ocsp_missing && conn_config->verifystatus &&
++ !octx->reused_session) {
++ /* verified, but OCSP stapling is required and server sent none */
++ *pverified = TRUE;
++ failf(data, "No OCSP response received");
++ return CURLE_SSL_INVALIDCERTSTATUS;
++ }
+ }
+ *pverified = !result;
+ return result;
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index a964868d872..2a27fd4d5bf 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -29,6 +29,7 @@ SRC_URI = " \
file://CVE-2026-8932.patch \
file://CVE-2026-11352.patch \
file://CVE-2026-11586.patch \
+ file://CVE-2026-7009.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 52/79] curl: patch CVE-2026-8925
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (50 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 51/79] curl: patch CVE-2026-7009 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 53/79] curl: patch CVE-2026-9080 Yoann Congal
` (26 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Pick patch per [1].
[1] https://curl.se/docs/CVE-2026-8925.html
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../curl/curl/CVE-2026-8925.patch | 57 +++++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
2 files changed, 58 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-8925.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-8925.patch b/meta/recipes-support/curl/curl/CVE-2026-8925.patch
new file mode 100644
index 00000000000..da486e6ac16
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-8925.patch
@@ -0,0 +1,57 @@
+From 3da249e1f0716c06644ed3522a37a8bf81808012 Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <commit@vsz.me>
+Date: Thu, 14 May 2026 14:35:21 +0200
+Subject: [PATCH] gsasl: fix potential double free
+
+Also:
+- require libgsasl 1.6.0+ (2010-12-14) for a `gsasl_finish()` that
+ handles a NULL argument.
+ Ref: https://gitlab.com/gsasl/gsasl/-/commit/b550032df8488a9ceaa3cfd4c634947d8f219717
+
+Reported-by: Joshua Rogers (Aisle Research)
+
+Closes #21609
+
+CVE: CVE-2026-8925
+Upstream-Status: Backport [https://github.com/curl/curl/commit/3da249e1f0716c06644ed3522a37a8bf81808012]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ docs/INTERNALS.md | 1 +
+ lib/vauth/gsasl.c | 5 +++++
+ 2 files changed, 6 insertions(+)
+
+diff --git a/docs/INTERNALS.md b/docs/INTERNALS.md
+index c145690a2c..77f2e43735 100644
+--- a/docs/INTERNALS.md
++++ b/docs/INTERNALS.md
+@@ -30,6 +30,7 @@ We aim to support these or later versions.
+ - c-ares 1.6.0 (2008-12-09)
+ - GnuTLS 3.6.5 (2018-12-01)
+ - libidn2 2.0.0 (2017-03-29)
++- libgsasl 1.6.0 (2010-12-14)
+ - LibreSSL 2.9.1 (2019-04-22)
+ - libssh 0.9.0 (2019-06-28)
+ - libssh2 1.9.0 (2019-06-20)
+diff --git a/lib/vauth/gsasl.c b/lib/vauth/gsasl.c
+index 3ea77eecd1..10a83fdb09 100644
+--- a/lib/vauth/gsasl.c
++++ b/lib/vauth/gsasl.c
+@@ -32,6 +32,10 @@
+
+ #include <gsasl.h>
+
++#if GSASL_VERSION_NUMBER < 0x010600
++#error "requires libgsasl 1.6.0+"
++#endif
++
+ bool Curl_auth_gsasl_is_supported(struct Curl_easy *data,
+ const char *mech,
+ struct gsasldata *gsasl)
+@@ -47,6 +51,7 @@ bool Curl_auth_gsasl_is_supported(struct Curl_easy *data,
+ res = gsasl_client_start(gsasl->ctx, mech, &gsasl->client);
+ if(res != GSASL_OK) {
+ gsasl_done(gsasl->ctx);
++ gsasl->ctx = NULL;
+ return FALSE;
+ }
+
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index 2a27fd4d5bf..bed11141ea6 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -30,6 +30,7 @@ SRC_URI = " \
file://CVE-2026-11352.patch \
file://CVE-2026-11586.patch \
file://CVE-2026-7009.patch \
+ file://CVE-2026-8925.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 53/79] curl: patch CVE-2026-9080
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (51 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 52/79] curl: patch CVE-2026-8925 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 54/79] curl: patch CVE-2026-9545 Yoann Congal
` (25 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Pick patch per [1].
[1] https://curl.se/docs/CVE-2026-9080.html
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../curl/curl/CVE-2026-9080.patch | 95 +++++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
2 files changed, 96 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9080.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-9080.patch b/meta/recipes-support/curl/curl/CVE-2026-9080.patch
new file mode 100644
index 00000000000..b1cf613f8a5
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-9080.patch
@@ -0,0 +1,95 @@
+From 5ab34cba42e4ee4282fe8bab43f311d51b9bf9bd Mon Sep 17 00:00:00 2001
+From: Daniel Stenberg <daniel@haxx.se>
+Date: Tue, 26 May 2026 09:52:19 +0200
+Subject: [PATCH] multi: handle pause in multi socket callback
+
+The mev_sh_entry object might be removed if curl_easy_pause() is called
+from within the socket callback.
+
+Introduced a 'magic' struct field to to 'mev_sh_entry' to make it easier
+to programmatically detect/assert if the pointer is bad - in debug
+builds.
+
+Reported-by: Joshua Rogers
+Closes #21748
+
+CVE: CVE-2026-9080
+Upstream-Status: Backport [https://github.com/curl/curl/commit/5ab34cba42e4ee4282fe8bab43f311d51b9bf9bd]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/multi_ev.c | 23 ++++++++++++++++++++---
+ 1 file changed, 20 insertions(+), 3 deletions(-)
+
+diff --git a/lib/multi_ev.c b/lib/multi_ev.c
+index 478d5a48d5..7ea3b2827e 100644
+--- a/lib/multi_ev.c
++++ b/lib/multi_ev.c
+@@ -40,6 +40,8 @@ static void mev_in_callback(struct Curl_multi *multi, bool value)
+ multi->in_callback = value;
+ }
+
++#define SH_ENTRY_MAGIC 0x570091d
++
+ /* Information about a socket for which we inform the libcurl application
+ * what to supervise (CURL_POLL_IN/CURL_POLL_OUT/CURL_POLL_REMOVE)
+ */
+@@ -51,6 +53,9 @@ struct mev_sh_entry {
+ * libcurl application to watch out for */
+ unsigned int readers; /* this many transfers want to read */
+ unsigned int writers; /* this many transfers want to write */
++#ifdef DEBUGBUILD
++ unsigned int magic;
++#endif
+ BIT(announced); /* this socket has been passed to the socket
+ callback at least once */
+ };
+@@ -75,6 +80,9 @@ static void mev_sh_entry_dtor(void *freethis)
+ {
+ struct mev_sh_entry *entry = (struct mev_sh_entry *)freethis;
+ Curl_uint32_spbset_destroy(&entry->xfers);
++#ifdef DEBUGBUILD
++ entry->magic = 0;
++#endif
+ curlx_free(entry);
+ }
+
+@@ -113,7 +121,9 @@ static struct mev_sh_entry *mev_sh_entry_add(struct Curl_hash *sh,
+ mev_sh_entry_dtor(check);
+ return NULL; /* major failure */
+ }
+-
++#ifdef DEBUGBUILD
++ check->magic = SH_ENTRY_MAGIC;
++#endif
+ return check; /* things are good in sockhash land */
+ }
+
+@@ -223,6 +233,7 @@ static CURLMcode mev_sh_entry_update(struct Curl_multi *multi,
+
+ /* we should only be called when the callback exists */
+ DEBUGASSERT(multi->socket_cb);
++ DEBUGASSERT(entry->magic == SH_ENTRY_MAGIC);
+ if(!multi->socket_cb)
+ return CURLM_OK;
+
+@@ -272,12 +283,18 @@ static CURLMcode mev_sh_entry_update(struct Curl_multi *multi,
+ rc = multi->socket_cb(data, s, comboaction, multi->socket_userp,
+ entry->user_data);
+ mev_in_callback(multi, FALSE);
+- entry->announced = TRUE;
+ if(rc == -1) {
+ multi->dead = TRUE;
+ return CURLM_ABORTED_BY_CALLBACK;
+ }
+- entry->action = (unsigned int)comboaction;
++ /* curl_easy_pause() is documented as callable from any callback; it
++ * re-enters mev_assess() which may free this 'entry'. Re-fetch. */
++ entry = mev_sh_entry_get(&multi->ev.sh_entries, s);
++ if(entry) {
++ DEBUGASSERT(entry->magic == SH_ENTRY_MAGIC);
++ entry->announced = TRUE;
++ entry->action = (unsigned int)comboaction;
++ }
+ return CURLM_OK;
+ }
+
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index bed11141ea6..4f28b63a746 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -31,6 +31,7 @@ SRC_URI = " \
file://CVE-2026-11586.patch \
file://CVE-2026-7009.patch \
file://CVE-2026-8925.patch \
+ file://CVE-2026-9080.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 54/79] curl: patch CVE-2026-9545
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (52 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 53/79] curl: patch CVE-2026-9080 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 55/79] curl: Fix for CVE-2026-9079 Yoann Congal
` (24 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Pick patch per [1].
Also pick additional patch for a clean cherry-pick.
[1] https://curl.se/docs/CVE-2026-9545.html
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../curl/curl/CVE-2026-9545-01.patch | 157 ++++++++++++++++++
.../curl/curl/CVE-2026-9545-02.patch | 67 ++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 2 +
3 files changed, 226 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9545-01.patch
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9545-02.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-9545-01.patch b/meta/recipes-support/curl/curl/CVE-2026-9545-01.patch
new file mode 100644
index 00000000000..5325c51e5e7
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-9545-01.patch
@@ -0,0 +1,157 @@
+From 41aaac61e215a827619b896d5b8588200cfdae28 Mon Sep 17 00:00:00 2001
+From: Stefan Eissing <stefan@eissing.org>
+Date: Wed, 18 Mar 2026 11:37:18 +0100
+Subject: [PATCH] lib: always use Curl_1st_fatal instead of Curl_1st_err
+
+Curl_1st_err() does not return the second error if the first result is
+CURLE_AGAIN. This may cause errors to not become noticeable when they
+should be.
+
+Replace all use of Curl_1st_err() with Curl_1st_fatal(), which handles
+CURLE_AGAIN as a not-a-real-error case.
+
+Closes #20980
+
+CVE: CVE-2026-9545
+Upstream-Status: Backport [https://github.com/curl/curl/commit/41aaac61e215a827619b896d5b8588200cfdae28]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/easy.c | 6 ++++--
+ lib/http.c | 2 +-
+ lib/multi.c | 2 +-
+ lib/url.c | 5 -----
+ lib/url.h | 7 -------
+ lib/vquic/curl_ngtcp2.c | 6 +++---
+ lib/vquic/curl_quiche.c | 4 ++--
+ 7 files changed, 11 insertions(+), 21 deletions(-)
+
+diff --git a/lib/easy.c b/lib/easy.c
+index 2c653b00e9..5a5dac4f56 100644
+--- a/lib/easy.c
++++ b/lib/easy.c
+@@ -1157,12 +1157,14 @@ CURLcode curl_easy_pause(CURL *d, int action)
+ if((send_paused != send_paused_new) ||
+ (send_paused_new != Curl_creader_is_paused(data))) {
+ changed = TRUE;
+- result = Curl_1st_err(result, Curl_xfer_pause_send(data, send_paused_new));
++ result = Curl_1st_fatal(
++ result, Curl_xfer_pause_send(data, send_paused_new));
+ }
+
+ if(recv_paused != recv_paused_new) {
+ changed = TRUE;
+- result = Curl_1st_err(result, Curl_xfer_pause_recv(data, recv_paused_new));
++ result = Curl_1st_fatal(
++ result, Curl_xfer_pause_recv(data, recv_paused_new));
+ }
+
+ /* If not completely pausing both directions now, run again in any case. */
+diff --git a/lib/http.c b/lib/http.c
+index aa34b5d14f..96e7b0de0c 100644
+--- a/lib/http.c
++++ b/lib/http.c
+@@ -4135,7 +4135,7 @@ static CURLcode http_on_response(struct Curl_easy *data,
+ out:
+ if(last_hd) {
+ /* if not written yet, write it now */
+- result = Curl_1st_err(
++ result = Curl_1st_fatal(
+ result, http_write_header(data, last_hd, last_hd_len));
+ }
+ if(conn_changed) {
+diff --git a/lib/multi.c b/lib/multi.c
+index 482c160fde..685bb01f0c 100644
+--- a/lib/multi.c
++++ b/lib/multi.c
+@@ -718,7 +718,7 @@ static CURLcode multi_done(struct Curl_easy *data,
+ }
+
+ /* Make sure that transfer client writes are really done now. */
+- result = Curl_1st_err(result, Curl_xfer_write_done(data, premature));
++ result = Curl_1st_fatal(result, Curl_xfer_write_done(data, premature));
+
+ /* Inform connection filters that this transfer is done */
+ Curl_conn_ev_data_done(data, premature);
+diff --git a/lib/url.c b/lib/url.c
+index a9ef60709a..cd06d6c626 100644
+--- a/lib/url.c
++++ b/lib/url.c
+@@ -3875,11 +3875,6 @@ void *Curl_conn_meta_get(struct connectdata *conn, const char *key)
+ return Curl_hash_pick(&conn->meta_hash, CURL_UNCONST(key), strlen(key) + 1);
+ }
+
+-CURLcode Curl_1st_err(CURLcode r1, CURLcode r2)
+-{
+- return r1 ? r1 : r2;
+-}
+-
+ CURLcode Curl_1st_fatal(CURLcode r1, CURLcode r2)
+ {
+ if(r1 && (r1 != CURLE_AGAIN))
+diff --git a/lib/url.h b/lib/url.h
+index 09bc33390f..0afa7eb26e 100644
+--- a/lib/url.h
++++ b/lib/url.h
+@@ -92,16 +92,9 @@ bool Curl_conn_seems_dead(struct connectdata *conn,
+ CURLcode Curl_conn_upkeep(struct Curl_easy *data,
+ struct connectdata *conn);
+
+-/**
+- * Always eval all arguments, return the first result != CURLE_OK.
+- * A non-short-circuit evaluation.
+- */
+-CURLcode Curl_1st_err(CURLcode r1, CURLcode r2);
+-
+ /**
+ * Always eval all arguments, return the first
+ * result != (CURLE_OK|CURLE_AGAIN) or `r1`.
+- * A non-short-circuit evaluation.
+ */
+ CURLcode Curl_1st_fatal(CURLcode r1, CURLcode r2);
+
+diff --git a/lib/vquic/curl_ngtcp2.c b/lib/vquic/curl_ngtcp2.c
+index ea79eaf747..04f660ac63 100644
+--- a/lib/vquic/curl_ngtcp2.c
++++ b/lib/vquic/curl_ngtcp2.c
+@@ -1461,8 +1461,8 @@ static CURLcode cf_ngtcp2_recv(struct Curl_cfilter *cf, struct Curl_easy *data,
+ result = CURLE_AGAIN;
+
+ out:
+- result = Curl_1st_err(result, cf_progress_egress(cf, data, &pktx));
+- result = Curl_1st_err(result, check_and_set_expiry(cf, data, &pktx));
++ result = Curl_1st_fatal(result, cf_progress_egress(cf, data, &pktx));
++ result = Curl_1st_fatal(result, check_and_set_expiry(cf, data, &pktx));
+ denied:
+ CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_recv(blen=%zu) -> %d, %zu",
+ stream ? stream->id : -1, blen, result, *pnread);
+@@ -1788,7 +1788,7 @@ static CURLcode cf_ngtcp2_send(struct Curl_cfilter *cf, struct Curl_easy *data,
+ result = cf_progress_egress(cf, data, &pktx);
+
+ out:
+- result = Curl_1st_err(result, check_and_set_expiry(cf, data, &pktx));
++ result = Curl_1st_fatal(result, check_and_set_expiry(cf, data, &pktx));
+ denied:
+ CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_send(len=%zu) -> %d, %zu",
+ stream ? stream->id : -1, len, result, *pnwritten);
+diff --git a/lib/vquic/curl_quiche.c b/lib/vquic/curl_quiche.c
+index a9a5ae6b99..4e8788aa1e 100644
+--- a/lib/vquic/curl_quiche.c
++++ b/lib/vquic/curl_quiche.c
+@@ -918,7 +918,7 @@ static CURLcode cf_quiche_recv(struct Curl_cfilter *cf, struct Curl_easy *data,
+ result = CURLE_AGAIN;
+
+ out:
+- result = Curl_1st_err(result, cf_flush_egress(cf, data));
++ result = Curl_1st_fatal(result, cf_flush_egress(cf, data));
+ if(*pnread > 0)
+ ctx->data_recvd += *pnread;
+ CURL_TRC_CF(data, cf, "[%" PRIu64 "] cf_recv(len=%zu) -> %d, %zu, total=%"
+@@ -1144,7 +1144,7 @@ static CURLcode cf_quiche_send(struct Curl_cfilter *cf, struct Curl_easy *data,
+ }
+
+ out:
+- result = Curl_1st_err(result, cf_flush_egress(cf, data));
++ result = Curl_1st_fatal(result, cf_flush_egress(cf, data));
+
+ CURL_TRC_CF(data, cf, "[%" PRIu64 "] cf_send(len=%zu) -> %d, %zu",
+ stream ? stream->id : (uint64_t)~0, len,
diff --git a/meta/recipes-support/curl/curl/CVE-2026-9545-02.patch b/meta/recipes-support/curl/curl/CVE-2026-9545-02.patch
new file mode 100644
index 00000000000..4fc60eb5c9a
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-9545-02.patch
@@ -0,0 +1,67 @@
+From 7b9613fa9b1a5e04301a3920eef58e8138dad05e Mon Sep 17 00:00:00 2001
+From: Stefan Eissing <stefan@eissing.org>
+Date: Thu, 21 May 2026 14:21:59 +0200
+Subject: [PATCH] ngtcp2: fail handshake directly
+
+When certificate verification fails, error out of the handshake
+callback, forcing ngtcp2 to stop processing the connection any further.
+
+Closes #21712
+
+CVE: CVE-2026-9545
+Upstream-Status: Backport [https://github.com/curl/curl/commit/7b9613fa9b1a5e04301a3920eef58e8138dad05e]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/vquic/curl_ngtcp2.c | 11 ++++++++++-
+ 1 file changed, 10 insertions(+), 1 deletion(-)
+
+diff --git a/lib/vquic/curl_ngtcp2.c b/lib/vquic/curl_ngtcp2.c
+index 4d27ebc0c1..fb7fd61889 100644
+--- a/lib/vquic/curl_ngtcp2.c
++++ b/lib/vquic/curl_ngtcp2.c
+@@ -504,7 +504,7 @@ static int cf_ngtcp2_handshake_completed(ngtcp2_conn *tconn, void *user_data)
+ data = CF_DATA_CURRENT(cf);
+ DEBUGASSERT(data);
+ if(!ctx || !data)
+- return NGHTTP3_ERR_CALLBACK_FAILURE;
++ return NGTCP2_ERR_CALLBACK_FAILURE;
+
+ ctx->handshake_at = *Curl_pgrs_now(data);
+ ctx->tls_handshake_complete = TRUE;
+@@ -512,6 +512,9 @@ static int cf_ngtcp2_handshake_completed(ngtcp2_conn *tconn, void *user_data)
+
+ ctx->tls_vrfy_result = Curl_vquic_tls_verify_peer(&ctx->tls, cf,
+ data, &ctx->peer);
++ if(ctx->tls_vrfy_result)
++ return NGTCP2_ERR_CALLBACK_FAILURE;
++
+ #ifdef CURLVERBOSE
+ if(Curl_trc_is_verbose(data)) {
+ const ngtcp2_transport_params *rp;
+@@ -1463,6 +1466,8 @@ static CURLcode cf_ngtcp2_recv(struct Curl_cfilter *cf, struct Curl_easy *data,
+ out:
+ result = Curl_1st_fatal(result, cf_progress_egress(cf, data, &pktx));
+ result = Curl_1st_fatal(result, check_and_set_expiry(cf, data, &pktx));
++ if(ctx->tls_vrfy_result)
++ result = ctx->tls_vrfy_result;
+ denied:
+ CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_recv(blen=%zu) -> %d, %zu",
+ stream ? stream->id : -1, blen, result, *pnread);
+@@ -1789,6 +1794,8 @@ static CURLcode cf_ngtcp2_send(struct Curl_cfilter *cf, struct Curl_easy *data,
+
+ out:
+ result = Curl_1st_fatal(result, check_and_set_expiry(cf, data, &pktx));
++ if(ctx->tls_vrfy_result)
++ result = ctx->tls_vrfy_result;
+ denied:
+ CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_send(len=%zu) -> %d, %zu",
+ stream ? stream->id : -1, len, result, *pnwritten);
+@@ -2717,6 +2724,8 @@ static CURLcode cf_ngtcp2_connect(struct Curl_cfilter *cf,
+ }
+
+ out:
++ if(ctx->tls_vrfy_result)
++ result = ctx->tls_vrfy_result;
+ if(ctx->qconn &&
+ ((result == CURLE_RECV_ERROR) || (result == CURLE_SEND_ERROR)) &&
+ ngtcp2_conn_in_draining_period(ctx->qconn)) {
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index 4f28b63a746..3695f8d083d 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -32,6 +32,8 @@ SRC_URI = " \
file://CVE-2026-7009.patch \
file://CVE-2026-8925.patch \
file://CVE-2026-9080.patch \
+ file://CVE-2026-9545-01.patch \
+ file://CVE-2026-9545-02.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 55/79] curl: Fix for CVE-2026-9079
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (53 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 54/79] curl: patch CVE-2026-9545 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 56/79] curl: set CVE_STATUS for CVE-2026-8458 Yoann Congal
` (23 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick patch from [1] mentioned in [2] taken from NVD report in [3].
[1] https://github.com/curl/curl/commit/88c7e16cceec816a2df45c89
[2] https://curl.se/docs/CVE-2026-9079.html
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-9079
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../curl/curl/CVE-2026-9079.patch | 289 ++++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
2 files changed, 290 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9079.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-9079.patch b/meta/recipes-support/curl/curl/CVE-2026-9079.patch
new file mode 100644
index 00000000000..c62914d586b
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-9079.patch
@@ -0,0 +1,289 @@
+From a9140d59cfb67394656d400e0f5f511d3b312b09 Mon Sep 17 00:00:00 2001
+From: Daniel Stenberg <daniel@haxx.se>
+Date: Wed, 20 May 2026 13:39:25 +0200
+Subject: [PATCH] setopt: clear proxy auth properly on NULL
+
+Verify NULLed proxy credentials with test1648
+
+Closes #21696
+
+CVE: CVE-2026-9079
+Upstream-Status: Backport [https://github.com/curl/curl/commit/88c7e16cceec816a2df45c89]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ lib/setopt.c | 12 ++--
+ tests/data/Makefile.am | 2 +-
+ tests/data/test1648 | 63 +++++++++++++++++
+ tests/libtest/Makefile.inc | 2 +-
+ tests/libtest/lib1648.c | 135 +++++++++++++++++++++++++++++++++++++
+ 5 files changed, 206 insertions(+), 8 deletions(-)
+ create mode 100644 tests/data/test1648
+ create mode 100644 tests/libtest/lib1648.c
+
+diff --git a/lib/setopt.c b/lib/setopt.c
+index a7f8a7071f..02e9a23094 100644
+--- a/lib/setopt.c
++++ b/lib/setopt.c
+@@ -1694,16 +1694,16 @@ static CURLcode setopt_cptr_proxy(struct Curl_easy *data, CURLoption option,
+ result = setstropt_userpwd(ptr, &u, &p);
+
+ /* URL decode the components */
+- if(!result && u) {
++ if(!result) {
+ Curl_safefree(s->str[STRING_PROXYUSERNAME]);
+- result = Curl_urldecode(u, 0, &s->str[STRING_PROXYUSERNAME], NULL,
+- REJECT_ZERO);
+- }
+- if(!result && p) {
+ Curl_safefree(s->str[STRING_PROXYPASSWORD]);
++ if(u)
++ result = Curl_urldecode(u, 0, &s->str[STRING_PROXYUSERNAME], NULL,
++ REJECT_ZERO);
++ }
++ if(!result && p)
+ result = Curl_urldecode(p, 0, &s->str[STRING_PROXYPASSWORD], NULL,
+ REJECT_ZERO);
+- }
+ curlx_free(u);
+ curlx_free(p);
+ break;
+diff --git a/tests/data/Makefile.am b/tests/data/Makefile.am
+index f9d20a9cc8..2c74a975df 100644
+--- a/tests/data/Makefile.am
++++ b/tests/data/Makefile.am
+@@ -218,7 +218,7 @@ test1620 test1621 test1622 test1623 test1624 \
+ \
+ test1630 test1631 test1632 test1633 test1634 test1635 test1636 test1637 \
+ \
+-test1640 test1641 test1642 test1643 test1647 \
++test1640 test1641 test1642 test1643 test1647 test1648 \
+ \
+ test1650 test1651 test1652 test1653 test1654 test1655 test1656 test1657 \
+ test1658 \
+diff --git a/tests/data/test1648 b/tests/data/test1648
+new file mode 100644
+index 0000000000..623f3c9a81
+--- /dev/null
++++ b/tests/data/test1648
+@@ -0,0 +1,63 @@
++<?xml version="1.0" encoding="US-ASCII"?>
++<testcase>
++<info>
++<keywords>
++HTTP
++HTTP GET
++HTTP proxy
++HTTP proxy auth
++</keywords>
++</info>
++
++# Server-side
++<reply>
++
++# this is returned first since we get no proxy-auth
++<data crlf="headers" nocheck="yes">
++HTTP/1.1 407 Authorization Required to proxy me my dear
++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345"
++Content-Length: 33
++
++And you should ignore this data.
++</data>
++
++</reply>
++
++# Client-side
++<client>
++<server>
++http
++</server>
++# tool is what to use instead of 'curl'
++<tool>
++lib%TESTNUMBER
++</tool>
++<features>
++proxy
++</features>
++<name>
++HTTP proxy with auth, change proxy, clear auth
++</name>
++<command>
++%HOSTIP %HTTPPORT
++</command>
++</client>
++
++# Verify data after the test has been "shot"
++<verify>
++<protocol crlf="headers">
++GET http://example.com/ HTTP/1.1
++Host: example.com
++Proxy-Authorization: Basic %b64[victim:secret]b64%
++Accept: */*
++Proxy-Connection: Keep-Alive
++
++GET http://example.com/ HTTP/1.1
++Host: example.com
++Accept: */*
++Proxy-Connection: Keep-Alive
++
++</protocol>
++
++</verify>
++</testcase>
+diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc
+index e938b87bc5..0803825e45 100644
+--- a/tests/libtest/Makefile.inc
++++ b/tests/libtest/Makefile.inc
+@@ -100,7 +100,7 @@ TESTS_C = \
+ lib1582.c lib1588.c \
+ lib1591.c lib1592.c lib1593.c lib1594.c lib1597.c \
+ lib1598.c lib1599.c \
+- lib1647.c \
++ lib1647.c lib1648.c \
+ lib1662.c \
+ lib1900.c lib1901.c lib1902.c lib1903.c lib1905.c lib1906.c lib1907.c \
+ lib1908.c lib1910.c lib1911.c lib1912.c lib1913.c \
+diff --git a/tests/libtest/lib1648.c b/tests/libtest/lib1648.c
+new file mode 100644
+index 0000000000..e97b2bdc88
+--- /dev/null
++++ b/tests/libtest/lib1648.c
+@@ -0,0 +1,135 @@
++/***************************************************************************
++ * _ _ ____ _
++ * Project ___| | | | _ \| |
++ * / __| | | | |_) | |
++ * | (__| |_| | _ <| |___
++ * \___|\___/|_| \_\_____|
++ *
++ * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
++ *
++ * This software is licensed as described in the file COPYING, which
++ * you should have received as part of this distribution. The terms
++ * are also available at https://curl.se/docs/copyright.html.
++ *
++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell
++ * copies of the Software, and permit persons to whom the Software is
++ * furnished to do so, under the terms of the COPYING file.
++ *
++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
++ * KIND, either express or implied.
++ *
++ * SPDX-License-Identifier: curl
++ *
++ ***************************************************************************/
++/*
++ * URL = host
++ * arg2 = port
++ */
++
++#include "first.h"
++
++/* this is meant to pick up the proxy from the environment variable */
++static CURLcode init1648(CURL *curl, const char *url, const char *proxy)
++{
++ CURLcode result = CURLE_OK;
++
++ res_easy_setopt(curl, CURLOPT_URL, url);
++ if(result)
++ goto init_failed;
++
++ res_easy_setopt(curl, CURLOPT_PROXY, proxy);
++ if(result)
++ goto init_failed;
++
++ res_easy_setopt(curl, CURLOPT_VERBOSE, 1L);
++ if(result)
++ goto init_failed;
++
++ return CURLE_OK; /* success */
++
++init_failed:
++ return result; /* failure */
++}
++
++static CURLcode run1648(CURL *curl, const char *url, const char *userpwd)
++{
++ CURLcode result = CURLE_OK;
++
++ result = init1648(curl, url, userpwd);
++ if(result)
++ return result;
++
++ return curl_easy_perform(curl);
++}
++
++#define GET_THIS "http://example.com/"
++
++/*
++ * First get the URL over 'firstproxy' with auth.
++ * Then clear the auth and get the URL again over 'secondproxy'.
++ */
++static CURLcode test_lib1648(const char *hostip)
++{
++ CURLcode result = CURLE_OK;
++ CURL *curl = NULL;
++ struct curl_slist *host = NULL;
++ struct curl_slist *host2 = NULL;
++ char proxy1_resolve[128];
++ char proxy2_resolve[128];
++ char proxy1_connect[128];
++ char proxy2_connect[128];
++
++ curl_msnprintf(proxy1_resolve, sizeof(proxy1_resolve),
++ "firstproxy:%s:%s", libtest_arg2, hostip);
++ curl_msnprintf(proxy2_resolve, sizeof(proxy2_resolve),
++ "secondproxy:%s:%s", libtest_arg2, hostip);
++
++ /* we connect to the fake host name but the right port number */
++ curl_msnprintf(proxy1_connect, sizeof(proxy1_connect),
++ "firstproxy:%s", libtest_arg2);
++ curl_msnprintf(proxy2_connect, sizeof(proxy2_connect),
++ "secondproxy:%s", libtest_arg2);
++
++ res_global_init(CURL_GLOBAL_ALL);
++ if(result)
++ return result;
++
++ curl = curl_easy_init();
++ if(!curl) {
++ curl_mfprintf(stderr, "curl_easy_init() failed\n");
++ curl_global_cleanup();
++ return TEST_ERR_MAJOR_BAD;
++ }
++
++ host = curl_slist_append(NULL, proxy1_resolve);
++ if(!host)
++ goto test_cleanup;
++ host2 = curl_slist_append(host, proxy2_resolve);
++ if(!host2)
++ goto test_cleanup;
++ host = host2;
++
++ start_test_timing();
++
++ easy_setopt(curl, CURLOPT_RESOLVE, host);
++ easy_setopt(curl, CURLOPT_PROXYUSERPWD, "victim:secret");
++
++ curl_mprintf("--- First get over %s\n", proxy1_connect);
++ result = run1648(curl, GET_THIS, proxy1_connect);
++ if(result)
++ goto test_cleanup;
++
++ easy_setopt(curl, CURLOPT_PROXYUSERPWD, NULL);
++
++ curl_mprintf("--- Then over '%s'\n", proxy2_connect);
++ result = run1648(curl, GET_THIS, proxy2_connect);
++
++test_cleanup:
++
++ /* proper cleanup sequence - type PB */
++
++ curl_easy_cleanup(curl);
++ curl_global_cleanup();
++ curl_slist_free_all(host);
++ return result;
++}
+--
+2.43.0
+
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index 3695f8d083d..cd56e2aaaf3 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -34,6 +34,7 @@ SRC_URI = " \
file://CVE-2026-9080.patch \
file://CVE-2026-9545-01.patch \
file://CVE-2026-9545-02.patch \
+ file://CVE-2026-9079.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 56/79] curl: set CVE_STATUS for CVE-2026-8458
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (54 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 55/79] curl: Fix for CVE-2026-9079 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 57/79] curl: Security Fix for CVE-2026-13608 Yoann Congal
` (22 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
CVE-2026-8458 allows a Negotiate-authenticated connection to be
incorrectly reused for a request using a different SASL service name.
Wrynose uses curl 8.19.0, which is within the affected version range.
The vulnerable code path on Linux requires both Negotiate authentication
and GSSAPI support, represented by the negotiate-auth and krb5
PACKAGECONFIG options.
The upstream fix [1] stores the SASL service name in struct Curl_creds
and includes it in connection-reuse comparisons. However, struct
Curl_creds was introduced by the credential-management rework in [2],
after curl 8.19.0. Therefore, the security fix cannot be cleanly
backported without introducing a substantial credential-management
refactor.
Use a conditional CVE_STATUS as the least invasive solution. Report the
CVE as unpatched when both krb5 and negotiate-auth are enabled. Otherwise,
mark it not-applicable-config because the vulnerable GSSAPI-backed
Negotiate implementation is not built. The default Wrynose configuration
enables negotiate-auth but does not enable krb5.
References:
[1] https://github.com/curl/curl/commit/5e99b73cf441d9c369768b9cd48b5389b9a2503d
[2] https://github.com/curl/curl/commit/8f71d0fde515aa4c68002477356c35bd79927729
[3] https://curl.se/docs/CVE-2026-8458.html
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index cd56e2aaaf3..dfc28539380 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -50,6 +50,7 @@ CVE_STATUS[CVE-2026-8924] = "not-applicable-config: public suffix list support i
CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', 'unpatched', 'not-applicable-config: applicable only with HTTP/2', d)}"
CVE_STATUS[CVE-2026-9547] = "not-applicable-config: vulnerable libssh backend is not enabled by the recipe"
CVE_STATUS[CVE-2026-12064] = "${@bb.utils.contains('PACKAGECONFIG', 'libssh2', 'unpatched', 'not-applicable-config: SCP/SFTP support is not enabled in PACKAGECONFIG', d)}"
+CVE_STATUS[CVE-2026-8458] = "${@bb.utils.contains('PACKAGECONFIG', 'krb5 negotiate-auth', 'unpatched', 'not-applicable-config: applicable only with GSS-API-backed Negotiate authentication', d)}"
inherit autotools pkgconfig binconfig multilib_header ptest
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 57/79] curl: Security Fix for CVE-2026-13608
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (55 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 56/79] curl: set CVE_STATUS for CVE-2026-8458 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 58/79] curl: Security Fix for CVE-2026-18924 Yoann Congal
` (21 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
[1] https://curl.se/docs/CVE-2026-13608.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-13608
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../curl/curl/CVE-2026-13608.patch | 48 +++++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
2 files changed, 49 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-13608.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-13608.patch b/meta/recipes-support/curl/curl/CVE-2026-13608.patch
new file mode 100644
index 00000000000..4df7595c8f0
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-13608.patch
@@ -0,0 +1,48 @@
+From 25df759f0f0c1aeaee066a4502bb36a8a86fb22e Mon Sep 17 00:00:00 2001
+From: Daniel Stenberg <daniel@haxx.se>
+Date: Mon, 29 Jun 2026 10:44:47 +0200
+Subject: [PATCH 1/5] openldap: handle Curl_sasl_continue() returns better
+
+Similar to how it gets treated already in other protocol handlers.
+
+Follow-up to eeca818b1e8d1e61c2d4
+
+Reported-by: Eunsoo Kim
+Closes #22213
+
+Upstream-Status: Backport [https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519]
+CVE: CVE-2026-13608
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ lib/openldap.c | 15 +++++++++++++--
+ 1 file changed, 13 insertions(+), 2 deletions(-)
+
+diff --git a/lib/openldap.c b/lib/openldap.c
+index 95f7681..4a1e93a 100644
+--- a/lib/openldap.c
++++ b/lib/openldap.c
+@@ -778,8 +778,19 @@ static CURLcode oldap_state_sasl_resp(struct Curl_easy *data,
+ }
+ else {
+ result = Curl_sasl_continue(&li->sasl, data, code, &progress);
+- if(!result && progress != SASL_INPROGRESS)
+- oldap_state(data, li, OLDAP_STOP);
++ if(!result) {
++ switch(progress) {
++ case SASL_DONE:
++ oldap_state(data, li, OLDAP_STOP); /* Authenticated */
++ break;
++ case SASL_IDLE: /* No mechanism left after cancellation */
++ failf(data, "Authentication cancelled");
++ result = CURLE_LOGIN_DENIED;
++ break;
++ default:
++ break;
++ }
++ }
+ }
+
+ if(li->servercred)
+--
+2.34.1
+
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index dfc28539380..21d887cb399 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -35,6 +35,7 @@ SRC_URI = " \
file://CVE-2026-9545-01.patch \
file://CVE-2026-9545-02.patch \
file://CVE-2026-9079.patch \
+ file://CVE-2026-13608.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 58/79] curl: Security Fix for CVE-2026-18924
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (56 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 57/79] curl: Security Fix for CVE-2026-13608 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 59/79] curl: Security Fix for CVE-2026-80229 Yoann Congal
` (20 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
[1] https://curl.se/docs/CVE-2026-18924.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-18924
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../curl/curl/CVE-2026-18924.patch | 39 +++++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
2 files changed, 40 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-18924.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-18924.patch b/meta/recipes-support/curl/curl/CVE-2026-18924.patch
new file mode 100644
index 00000000000..fbf452e4e9c
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-18924.patch
@@ -0,0 +1,39 @@
+From 90325ff0444cbdff368bda5d26d6405a0bb6ee43 Mon Sep 17 00:00:00 2001
+From: Daniel Stenberg <daniel@haxx.se>
+Date: Wed, 5 Aug 2026 10:02:53 +0200
+Subject: [PATCH] http2: make server push transfers inherit share from parent
+
+Reported-by: Stephan Zeisberg
+Closes #22488
+
+Upstream-Status: Backport [https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43]
+CVE: CVE-2026-18924
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ lib/http2.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+diff --git a/lib/http2.c b/lib/http2.c
+index e1c5798..2ef1c28 100644
+--- a/lib/http2.c
++++ b/lib/http2.c
+@@ -46,6 +46,7 @@
+ #include "bufref.h"
+ #include "curlx/dynbuf.h"
+ #include "headers.h"
++#include "curl_share.h"
+
+ #if (NGHTTP2_VERSION_NUM < 0x010c00)
+ #error too old nghttp2 version, upgrade!
+@@ -709,6 +710,8 @@ static struct Curl_easy *h2_duphandle(struct Curl_cfilter *cf,
+ struct h2_stream_ctx *second_stream;
+ http2_data_setup(cf, second, &second_stream);
+ second->state.priority.weight = data->state.priority.weight;
++ if(data->share)
++ (void)Curl_share_easy_link(second, data->share);
+ }
+ return second;
+ }
+--
+2.34.1
+
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index 21d887cb399..ccf8de0b90e 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -36,6 +36,7 @@ SRC_URI = " \
file://CVE-2026-9545-02.patch \
file://CVE-2026-9079.patch \
file://CVE-2026-13608.patch \
+ file://CVE-2026-18924.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 59/79] curl: Security Fix for CVE-2026-80229
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (57 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 58/79] curl: Security Fix for CVE-2026-18924 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 60/79] curl: set CVE_STATUS for CVE-2026-82209 Yoann Congal
` (19 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
[1] https://curl.se/docs/CVE-2026-80229.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-80229
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../curl/curl/CVE-2026-80229.patch | 35 +++++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
2 files changed, 36 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-80229.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-80229.patch b/meta/recipes-support/curl/curl/CVE-2026-80229.patch
new file mode 100644
index 00000000000..74be963fa4d
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-80229.patch
@@ -0,0 +1,35 @@
+From 272d5928188bc2171fdeba81027b24145a033fb2 Mon Sep 17 00:00:00 2001
+From: Daniel Stenberg <daniel@haxx.se>
+Date: Tue, 25 Aug 2026 11:14:30 +0200
+Subject: [PATCH 3/5] openssl: avoid conn reuse if provider is used
+
+Reported-by: Stanislav Fort
+
+Closes #22665
+
+Upstream-Status: Backport [https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb]
+CVE: CVE-2026-80229
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ lib/vtls/openssl.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/lib/vtls/openssl.c b/lib/vtls/openssl.c
+index 9cbab14..1d0f7b7 100644
+--- a/lib/vtls/openssl.c
++++ b/lib/vtls/openssl.c
+@@ -3753,6 +3753,11 @@ CURLcode Curl_ossl_ctx_init(struct ossl_ctx *octx,
+ ossl_strerror(ERR_peek_error(), error_buffer, sizeof(error_buffer)));
+ return CURLE_OUT_OF_MEMORY;
+ }
++#ifdef OPENSSL_HAS_PROVIDERS
++ if(data->state.libctx)
++ /* forbid connection reuse with provider/engine use */
++ connclose(data->conn, "forbid connection reuse with provider/engine use");
++#endif
+
+ if(cb_setup) {
+ result = cb_setup(cf, data, cb_user_data);
+--
+2.34.1
+
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index ccf8de0b90e..33aed045117 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -37,6 +37,7 @@ SRC_URI = " \
file://CVE-2026-9079.patch \
file://CVE-2026-13608.patch \
file://CVE-2026-18924.patch \
+ file://CVE-2026-80229.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 60/79] curl: set CVE_STATUS for CVE-2026-82209
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (58 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 59/79] curl: Security Fix for CVE-2026-80229 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 61/79] curl: patch CVE-2026-9546 Yoann Congal
` (18 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Analysis:
- The problem only exists when curl is built with libpsl support enabled.[1]
- The recipe is built with "--without-libpsl" option.
- Hence, ignoring the CVE for this recipe.
Reference:
[1] https://curl.se/docs/CVE-2026-82209.html
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index 33aed045117..f6ddc4aa230 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -54,6 +54,7 @@ CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', '
CVE_STATUS[CVE-2026-9547] = "not-applicable-config: vulnerable libssh backend is not enabled by the recipe"
CVE_STATUS[CVE-2026-12064] = "${@bb.utils.contains('PACKAGECONFIG', 'libssh2', 'unpatched', 'not-applicable-config: SCP/SFTP support is not enabled in PACKAGECONFIG', d)}"
CVE_STATUS[CVE-2026-8458] = "${@bb.utils.contains('PACKAGECONFIG', 'krb5 negotiate-auth', 'unpatched', 'not-applicable-config: applicable only with GSS-API-backed Negotiate authentication', d)}"
+CVE_STATUS[CVE-2026-82209] = "not-applicable-config: public suffix list support is disabled by the recipe with --without-libpsl"
inherit autotools pkgconfig binconfig multilib_header ptest
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 61/79] curl: patch CVE-2026-9546
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (59 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 60/79] curl: set CVE_STATUS for CVE-2026-82209 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 62/79] libpcap: Fix CVE-2026-0799 Yoann Congal
` (17 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Pick patch per [1].
Pick also a precondition patch (containing if clause to else which is
added by the actual patch).
Resolve conflicts in test makefiles caused by differences in available
test suites.
[1] https://curl.se/docs/CVE-2026-9546.html
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: refreshed patches on Makefile test lists]
---
.../curl/curl/CVE-2026-9546-01.patch | 227 ++++++++++++++++++
.../curl/curl/CVE-2026-9546-02.patch | 218 +++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 2 +
3 files changed, 447 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9546-01.patch
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9546-02.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-9546-01.patch b/meta/recipes-support/curl/curl/CVE-2026-9546-01.patch
new file mode 100644
index 00000000000..74dc7015559
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-9546-01.patch
@@ -0,0 +1,227 @@
+From fa057ea3dedb04f93672ec95ee964f1f02ec0ecf Mon Sep 17 00:00:00 2001
+From: Daniel Stenberg <daniel@haxx.se>
+Date: Wed, 15 Apr 2026 08:11:33 +0200
+Subject: [PATCH] transfer: clear the old autoreferer
+
+Verify in test 2505
+
+Closes #21322
+
+CVE: CVE-2026-9546
+Upstream-Status: Backport [https://github.com/curl/curl/commit/fa057ea3dedb04f93672ec95ee964f1f02ec0ecf]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/setopt.c | 1 -
+ lib/transfer.c | 5 +++
+ tests/data/Makefile.am | 2 +-
+ tests/data/test2505 | 67 +++++++++++++++++++++++++++++++++++
+ tests/libtest/Makefile.inc | 2 +-
+ tests/libtest/lib2505.c | 71 ++++++++++++++++++++++++++++++++++++++
+ 6 files changed, 145 insertions(+), 3 deletions(-)
+ create mode 100644 tests/data/test2505
+ create mode 100644 tests/libtest/lib2505.c
+
+diff --git a/lib/setopt.c b/lib/setopt.c
+index dae4218b70..e832ef1afd 100644
+--- a/lib/setopt.c
++++ b/lib/setopt.c
+@@ -2015,7 +2015,6 @@ static CURLcode setopt_cptr(struct Curl_easy *data, CURLoption option,
+ * String to set in the HTTP Referer: field.
+ */
+ result = Curl_setstropt(&s->str[STRING_SET_REFERER], ptr);
+- Curl_bufref_set(&data->state.referer, s->str[STRING_SET_REFERER], 0, NULL);
+ break;
+
+ case CURLOPT_USERAGENT:
+diff --git a/lib/transfer.c b/lib/transfer.c
+index a2fce9331b..fd1a903dab 100644
+--- a/lib/transfer.c
++++ b/lib/transfer.c
+@@ -535,6 +535,11 @@ CURLcode Curl_pretransfer(struct Curl_easy *data)
+ data->state.authproxy.want = data->set.proxyauth;
+ Curl_safefree(data->info.wouldredirect);
+ Curl_data_priority_clear_state(data);
++ if(data->set.http_auto_referer)
++ Curl_bufref_free(&data->state.referer);
++ if(data->set.str[STRING_SET_REFERER])
++ Curl_bufref_set(&data->state.referer, data->set.str[STRING_SET_REFERER],
++ 0, NULL);
+
+ if(data->state.httpreq == HTTPREQ_PUT)
+ data->state.infilesize = data->set.filesize;
+diff --git a/tests/data/Makefile.am b/tests/data/Makefile.am
+index 1e84b26820..238da5331c 100644
+--- a/tests/data/Makefile.am
++++ b/tests/data/Makefile.am
+@@ -265,7 +265,7 @@ test2309 \
+ \
+ test2400 test2401 test2402 test2403 test2404 test2405 test2406 test2407 \
+ \
+-test2500 test2501 test2502 test2503 test2504 test2506 \
++test2500 test2501 test2502 test2503 test2504 test2505 test2506 \
+ \
+ test2600 test2601 test2602 test2603 test2604 test2605 \
+ \
+diff --git a/tests/data/test2505 b/tests/data/test2505
+new file mode 100644
+index 0000000000..8fac590b37
+--- /dev/null
++++ b/tests/data/test2505
+@@ -0,0 +1,67 @@
++<?xml version="1.0" encoding="US-ASCII"?>
++<testcase>
++<info>
++<keywords>
++HTTP
++referer
++autoreferer
++</keywords>
++</info>
++
++# Server-side
++<reply>
++<data crlf="headers" nocheck="yes">
++HTTP/1.1 301 redirect
++Date: Tue, 09 Nov 2010 14:49:00 GMT
++Server: server.example.com
++Content-Length: 47
++Location: %TESTNUMBER0002
++
++file contents should appear once for each file
++</data>
++
++<data2 crlf="headers" nocheck="yes">
++HTTP/1.1 200 OK
++Date: Tue, 09 Nov 2010 14:49:00 GMT
++Server: server.example.com
++Content-Length: 47
++
++file contents should appear once for each file
++</data2>
++</reply>
++
++# Client-side
++<client>
++<server>
++http
++</server>
++<tool>
++lib%TESTNUMBER
++</tool>
++<name>
++verify CURLOPT_AUTOREFERER switched off
++</name>
++<command>
++http://%HOSTIP:%HTTPPORT
++</command>
++</client>
++
++# Verify data after the test has been "shot"
++<verify>
++<protocol crlf="headers">
++GET / HTTP/1.1
++Host: %HOSTIP:%HTTPPORT
++Accept: */*
++
++GET /%TESTNUMBER0002 HTTP/1.1
++Host: %HOSTIP:%HTTPPORT
++Accept: */*
++Referer: http://%HOSTIP:%HTTPPORT/
++
++GET / HTTP/1.1
++Host: %HOSTIP:%HTTPPORT
++Accept: */*
++
++</protocol>
++</verify>
++</testcase>
+diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc
+index 249c6fda87..bdf8a1dbea 100644
+--- a/tests/libtest/Makefile.inc
++++ b/tests/libtest/Makefile.inc
+@@ -113,7 +113,7 @@ TESTS_C = \
+ lib2023.c lib2032.c lib2082.c \
+ lib2301.c lib2302.c lib2304.c lib2306.c lib2308.c lib2309.c \
+ lib2402.c lib2404.c lib2405.c \
+- lib2502.c lib2504.c lib2506.c \
++ lib2502.c lib2504.c lib2505.c lib2506.c \
+ lib2700.c \
+ lib3010.c lib3025.c lib3026.c lib3027.c lib3033.c lib3034.c \
+ lib3100.c lib3101.c lib3102.c lib3103.c lib3104.c lib3105.c \
+diff --git a/tests/libtest/lib2505.c b/tests/libtest/lib2505.c
+new file mode 100644
+index 0000000000..c170259874
+--- /dev/null
++++ b/tests/libtest/lib2505.c
+@@ -0,0 +1,71 @@
++/***************************************************************************
++ * _ _ ____ _
++ * Project ___| | | | _ \| |
++ * / __| | | | |_) | |
++ * | (__| |_| | _ <| |___
++ * \___|\___/|_| \_\_____|
++ *
++ * Copyright (C) Linus Nielsen Feltzing <linus@haxx.se>
++ *
++ * This software is licensed as described in the file COPYING, which
++ * you should have received as part of this distribution. The terms
++ * are also available at https://curl.se/docs/copyright.html.
++ *
++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell
++ * copies of the Software, and permit persons to whom the Software is
++ * furnished to do so, under the terms of the COPYING file.
++ *
++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
++ * KIND, either express or implied.
++ *
++ * SPDX-License-Identifier: curl
++ *
++ ***************************************************************************/
++#include "first.h"
++
++#include "testtrace.h"
++
++static size_t sink2505(char *ptr, size_t size, size_t nmemb, void *ud)
++{
++ (void)ptr;
++ (void)ud;
++ return size * nmemb;
++}
++
++static CURLcode test_lib2505(const char *URL)
++{
++ CURL *curl;
++ CURLcode result = CURLE_OUT_OF_MEMORY;
++
++ if(curl_global_init(CURL_GLOBAL_ALL) != CURLE_OK) {
++ curl_mfprintf(stderr, "curl_global_init() failed\n");
++ return TEST_ERR_MAJOR_BAD;
++ }
++
++ curl = curl_easy_init();
++ if(!curl) {
++ curl_mfprintf(stderr, "curl_easy_init() failed\n");
++ curl_global_cleanup();
++ return TEST_ERR_MAJOR_BAD;
++ }
++
++ test_setopt(curl, CURLOPT_WRITEFUNCTION, sink2505);
++ test_setopt(curl, CURLOPT_AUTOREFERER, 1L);
++ test_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L);
++ test_setopt(curl, CURLOPT_URL, URL);
++
++ result = curl_easy_perform(curl);
++ curl_mprintf("req1=%d\n", (int)result);
++
++ test_setopt(curl, CURLOPT_FOLLOWLOCATION, 0L);
++ test_setopt(curl, CURLOPT_URL, URL);
++
++ result = curl_easy_perform(curl);
++ curl_mprintf("req2=%d\n", (int)result);
++
++test_cleanup:
++ curl_easy_cleanup(curl);
++ curl_global_cleanup();
++
++ return result;
++}
diff --git a/meta/recipes-support/curl/curl/CVE-2026-9546-02.patch b/meta/recipes-support/curl/curl/CVE-2026-9546-02.patch
new file mode 100644
index 00000000000..d4842824ff7
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-9546-02.patch
@@ -0,0 +1,218 @@
+From 862e8a74a84478d82973471b4f49dc2746c1780e Mon Sep 17 00:00:00 2001
+From: Daniel Stenberg <daniel@haxx.se>
+Date: Mon, 25 May 2026 16:43:00 +0200
+Subject: [PATCH] transfer: clear referer when set to NULL
+
+Verify in test 1649
+
+Closes #21741
+
+CVE: CVE-2026-9546
+Upstream-Status: Backport [https://github.com/curl/curl/commit/862e8a74a84478d82973471b4f49dc2746c1780e]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/transfer.c | 2 +
+ tests/data/Makefile.am | 2 +-
+ tests/data/test1649 | 55 +++++++++++++++++++++++
+ tests/libtest/Makefile.inc | 2 +-
+ tests/libtest/lib1649.c | 90 ++++++++++++++++++++++++++++++++++++++
+ 5 files changed, 149 insertions(+), 2 deletions(-)
+ create mode 100644 tests/data/test1649
+ create mode 100644 tests/libtest/lib1649.c
+
+diff --git a/lib/transfer.c b/lib/transfer.c
+index 9998d2d..9b55913 100644
+--- a/lib/transfer.c
++++ b/lib/transfer.c
+@@ -540,6 +540,8 @@ CURLcode Curl_pretransfer(struct Curl_easy *data)
+ if(data->set.str[STRING_SET_REFERER])
+ Curl_bufref_set(&data->state.referer, data->set.str[STRING_SET_REFERER],
+ 0, NULL);
++ else
++ Curl_bufref_free(&data->state.referer);
+
+ if(data->state.httpreq == HTTPREQ_PUT)
+ data->state.infilesize = data->set.filesize;
+diff --git a/tests/data/Makefile.am b/tests/data/Makefile.am
+index deb635e..7c3766c 100644
+--- a/tests/data/Makefile.am
++++ b/tests/data/Makefile.am
+@@ -218,7 +218,7 @@ test1620 test1621 test1622 test1623 test1624 \
+ \
+ test1630 test1631 test1632 test1633 test1634 test1635 test1636 test1637 \
+ \
+-test1640 test1641 test1642 test1643 test1647 test1648 \
++test1640 test1641 test1642 test1643 test1647 test1648 test1649 \
+ \
+ test1650 test1651 test1652 test1653 test1654 test1655 test1656 test1657 \
+ test1658 \
+diff --git a/tests/data/test1649 b/tests/data/test1649
+new file mode 100644
+index 0000000..d2fd779
+--- /dev/null
++++ b/tests/data/test1649
+@@ -0,0 +1,55 @@
++<?xml version="1.0" encoding="US-ASCII"?>
++<testcase>
++<info>
++<keywords>
++HTTP
++Referer
++</keywords>
++</info>
++
++# Server-side
++<reply>
++
++# this is returned first since we get no proxy-auth
++<data crlf="headers" nocheck="yes">
++HTTP/1.1 200 OK
++Content-Length: 6
++
++hello
++</data>
++
++</reply>
++
++# Client-side
++<client>
++<server>
++http
++</server>
++
++<tool>
++lib%TESTNUMBER
++</tool>
++<name>
++Set referer first then NULL it
++</name>
++<command>
++http://%HOSTIP:%HTTPPORT
++</command>
++</client>
++
++# Verify data after the test has been "shot"
++<verify>
++<protocol crlf="headers">
++GET / HTTP/1.1
++Host: %HOSTIP:%HTTPPORT
++Accept: */*
++Referer: https://secret.example.com/
++
++GET / HTTP/1.1
++Host: %HOSTIP:%HTTPPORT
++Accept: */*
++
++</protocol>
++
++</verify>
++</testcase>
+diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc
+index 655c32d..d7af26f 100644
+--- a/tests/libtest/Makefile.inc
++++ b/tests/libtest/Makefile.inc
+@@ -100,7 +100,7 @@ TESTS_C = \
+ lib1582.c lib1588.c \
+ lib1591.c lib1592.c lib1593.c lib1594.c lib1597.c \
+ lib1598.c lib1599.c \
+- lib1647.c lib1648.c \
++ lib1647.c lib1648.c lib1649.c \
+ lib1662.c \
+ lib1900.c lib1901.c lib1902.c lib1903.c lib1905.c lib1906.c lib1907.c \
+ lib1908.c lib1910.c lib1911.c lib1912.c lib1913.c \
+diff --git a/tests/libtest/lib1649.c b/tests/libtest/lib1649.c
+new file mode 100644
+index 0000000..2dd66c0
+--- /dev/null
++++ b/tests/libtest/lib1649.c
+@@ -0,0 +1,90 @@
++/***************************************************************************
++ * _ _ ____ _
++ * Project ___| | | | _ \| |
++ * / __| | | | |_) | |
++ * | (__| |_| | _ <| |___
++ * \___|\___/|_| \_\_____|
++ *
++ * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
++ *
++ * This software is licensed as described in the file COPYING, which
++ * you should have received as part of this distribution. The terms
++ * are also available at https://curl.se/docs/copyright.html.
++ *
++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell
++ * copies of the Software, and permit persons to whom the Software is
++ * furnished to do so, under the terms of the COPYING file.
++ *
++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
++ * KIND, either express or implied.
++ *
++ * SPDX-License-Identifier: curl
++ *
++ ***************************************************************************/
++
++#include "first.h"
++
++/* this is meant to pick up the proxy from the environment variable */
++static CURLcode init1649(CURL *curl, const char *url)
++{
++ CURLcode result = CURLE_OK;
++
++ res_easy_setopt(curl, CURLOPT_URL, url);
++ if(result)
++ goto init_failed;
++
++ res_easy_setopt(curl, CURLOPT_VERBOSE, 1L);
++ if(result)
++ goto init_failed;
++
++ return CURLE_OK; /* success */
++
++init_failed:
++ return result; /* failure */
++}
++
++static CURLcode run1649(CURL *curl, const char *url)
++{
++ CURLcode result = CURLE_OK;
++
++ result = init1649(curl, url);
++ if(result)
++ return result;
++
++ return curl_easy_perform(curl);
++}
++
++static CURLcode test_lib1649(const char *URL)
++{
++ CURLcode result = CURLE_OK;
++ CURL *curl = NULL;
++
++ res_global_init(CURL_GLOBAL_ALL);
++ if(result)
++ return result;
++
++ curl = curl_easy_init();
++ if(!curl) {
++ curl_mfprintf(stderr, "curl_easy_init() failed\n");
++ curl_global_cleanup();
++ return TEST_ERR_MAJOR_BAD;
++ }
++
++ start_test_timing();
++
++ easy_setopt(curl, CURLOPT_REFERER, "https://secret.example.com/");
++
++ result = run1649(curl, URL);
++ if(result)
++ goto test_cleanup;
++
++ /* reset it */
++ easy_setopt(curl, CURLOPT_REFERER, NULL);
++
++ result = run1649(curl, URL);
++
++test_cleanup:
++ curl_easy_cleanup(curl);
++ curl_global_cleanup();
++ return result;
++}
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index f6ddc4aa230..fd0fbcea692 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -38,6 +38,8 @@ SRC_URI = " \
file://CVE-2026-13608.patch \
file://CVE-2026-18924.patch \
file://CVE-2026-80229.patch \
+ file://CVE-2026-9546-01.patch \
+ file://CVE-2026-9546-02.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 62/79] libpcap: Fix CVE-2026-0799
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (60 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 61/79] curl: patch CVE-2026-9546 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 63/79] libpcap: Fix CVE-2026-31912 Yoann Congal
` (16 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-0799
Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libpcap/libpcap/01-CVE-2026-0799.patch | 67 +++++++++++++++++++
.../libpcap/libpcap_1.10.6.bb | 1 +
2 files changed, 68 insertions(+)
create mode 100644 meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch
diff --git a/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch
new file mode 100644
index 00000000000..7c40faa608d
--- /dev/null
+++ b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch
@@ -0,0 +1,67 @@
+From 3c55fdefa576c7a06feab86a9e4341be414de49b Mon Sep 17 00:00:00 2001
+From: Denis Ovsienko <denis@ovsienko.info>
+Date: Thu, 30 Jul 2026 13:33:41 +0100
+Subject: [PATCH] CVE-2026-0799: Access M[] safely in the BPF interpreter.
+
+Include Security identified and reported this problem as a potential
+vulnerability in 2018 (case reference "I7"). Their work was sponsored
+by Mozilla under the Secure Open Source program. The vulnerability has
+been independently confirmed only recently.
+
+The current revision of pcapint_filter_with_aux_data() can, but does not
+check whether a scratch memory register index is valid in the "ld M[k]",
+"ldx M[k]", "st M[k]" and "stx M[k]" BPF instructions, and assumes this
+is always the case. This holds for programs that have been generated or
+validated by libpcap.
+
+However, this does not necessarily hold for programs that come via
+pcap_offline_filter() or [deprecated] bpf_filter() from an external
+source and have not been explicitly validated. If the interpreter
+executes such a program with an invalid index, it will read/write the
+process memory at arbitrary locations starting at the current stack
+frame. Depending on the address, the memory layout and the OS, this can
+result in stack buffer overflow, SIGSEGV, SIGBUS or other effects. To
+fix this, in the interpreter reject the packet if the index is invalid.
+
+(backported from commit 569f8fd3524192acbabf93c9cd704471bb38f84a)
+
+(cherry picked from commit 48e8960a7108e9e828f9d7bdc7e97bdab841aec7)
+
+Notes on backporting to 1.10.6:
+ - The upstream CHANGES/changelog hunk is not backported.
+
+Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7]
+CVE: CVE-2026-0799
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+diff --git a/bpf_filter.c b/bpf_filter.c
+index 9b899bbb..510dbd9c 100644
+--- a/bpf_filter.c
++++ b/bpf_filter.c
+@@ -217,18 +217,26 @@ DIAG_ON_DEFAULT_ONLY_SWITCH
+ continue;
+
+ case BPF_LD|BPF_MEM:
++ if (pc->k >= BPF_MEMWORDS)
++ return 0;
+ A = mem[pc->k];
+ continue;
+
+ case BPF_LDX|BPF_MEM:
++ if (pc->k >= BPF_MEMWORDS)
++ return 0;
+ X = mem[pc->k];
+ continue;
+
+ case BPF_ST:
++ if (pc->k >= BPF_MEMWORDS)
++ return 0;
+ mem[pc->k] = A;
+ continue;
+
+ case BPF_STX:
++ if (pc->k >= BPF_MEMWORDS)
++ return 0;
+ mem[pc->k] = X;
+ continue;
+
diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
index d381a4eb2fe..265c46e3bd0 100644
--- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
+++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
@@ -12,6 +12,7 @@ DEPENDS = "flex-native bison-native"
SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \
file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \
+ file://01-CVE-2026-0799.patch \
"
SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 63/79] libpcap: Fix CVE-2026-31912
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (61 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 62/79] libpcap: Fix CVE-2026-0799 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 64/79] libpcap: Fix CVE-2026-31911 Yoann Congal
` (15 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31912
Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libpcap/libpcap/02-CVE-2026-31912.patch | 597 ++++++++++++++++++
.../libpcap/libpcap_1.10.6.bb | 1 +
2 files changed, 598 insertions(+)
create mode 100644 meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch
diff --git a/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch
new file mode 100644
index 00000000000..ceae734ff7b
--- /dev/null
+++ b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch
@@ -0,0 +1,597 @@
+From 09e04074ddfbca5fa33693c6e2d4f01a74857f65 Mon Sep 17 00:00:00 2001
+From: Denis Ovsienko <denis@ovsienko.info>
+Date: Thu, 30 Jul 2026 13:33:55 +0100
+Subject: [PATCH] CVE-2026-31912: Mind the program bounds in
+ pcap_offline_filter().
+
+The current revision of pcapint_filter_with_aux_data() does not know the
+number of instructions in the filter program, it assumes the program
+counter always remains within the bounds of the provided filter program
+and always reaches a return instruction. This holds for programs that
+have been generated or validated by libpcap.
+
+However, this does not necessarily hold for programs that come from an
+external source via pcap_offline_filter() or [deprecated] bpf_filter()
+and have not been explicitly validated. If the interpreter executes
+such a program and advances the program counter beyond the last
+instruction, it will be interpreting memory space after the filter
+program as BPF instructions, which in the current implementation will
+eventually cause either abort() (another commit addresses that) or
+SIGSEGV.
+
+To fix the latter problem, in pcapint_filter_with_aux_data() add a
+parameter for the number of instructions in the program and reject the
+packet as soon as (or just before) the program counter goes out of
+bounds. Update all incoming code paths to specify the length; also in
+pcap_offline_filter(3PCAP) make it clear the function now requires the
+'bf_len' member to be set correctly and uses it.
+
+(backported from commit d1209988c74dd9330659898d3b676ee6bbe1c551)
+
+(cherry picked from commit d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9)
+
+Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9]
+CVE: CVE-2026-31912
+
+Notes on backporting to 1.10.6:
+ - Adjusted the pcapint_filter() call sites in pcap-dag.c, pcap-netmap.c and
+ pcap-snf.c to the 1.10.6 code base. In 1.10.7 these were already touched by
+ the unrelated "low snaplen" fixes (commits d5192db3, fb87fdeb, b0caefe8),
+ which are not part of this CVE and are not backported here; only the new
+ bf_len argument is added to each call.
+ - In bpf_filter.c the scratch-memory-store zero-initialisation and the removal
+ of the stray BPF_S_ANC_* enum (1.10.7-only cleanups) are not present in
+ 1.10.6, so only the new pc0 declaration and bounds checks from this commit
+ are added.
+ - The upstream CHANGES/changelog hunk is not backported.
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+diff --git a/bpf_filter.c b/bpf_filter.c
+index 510dbd9c..4f9adeea 100644
+--- a/bpf_filter.c
++++ b/bpf_filter.c
+@@ -70,6 +70,24 @@ enum {
+ BPF_S_ANC_VLAN_TAG_PRESENT,
+ };
+
++/*
++ * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the
++ * userland interpreter in libpcap is meant to support much longer filter
++ * programs. In the latter case it is important that BPF_MAXINSNS does not
++ * interfere with the safety checks in the validator and the interpreter:
++ * (BPF_MAXINSNS + UINT8_MAX) * sizeof(struct bpf_insn) < UINT32_MAX
++ * It makes the most sense to be able to interpret as many instructions as
++ * pcap_compile() can produce, without optimization, for a valid filter
++ * expression before it consumes as much memory as the current definitions of
++ * NCHUNKS and CHUNKSIZE() allow. For some expressions this can be almost
++ * 1.53 million instructions on a 64-bit machine and twice as many on a 32-bit
++ * machine.
++ */
++#ifdef BPF_MAXINSNS
++#undef BPF_MAXINSNS
++#endif
++#define BPF_MAXINSNS 3060000U
++
+ /*
+ * Execute the filter program starting at pc on the packet p
+ * wirelen is the length of the original packet
+@@ -84,12 +102,14 @@ enum {
+ */
+ #if defined(SKF_AD_VLAN_TAG_PRESENT)
+ u_int
+-pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p,
+- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data)
++pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen,
++ const u_char *p, const u_int wirelen, const u_int buflen,
++ const struct pcap_bpf_aux_data *aux_data)
+ #else
+ u_int
+-pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p,
+- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data _U_)
++pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen,
++ const u_char *p, const u_int wirelen, const u_int buflen,
++ const struct pcap_bpf_aux_data *aux_data _U_)
+ #endif
+ {
+ register uint32_t A, X;
+@@ -99,13 +119,36 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p,
+ if (pc == 0)
+ /*
+ * No filter means accept all.
++ * In this case the value of 'proglen' is irrelevant.
+ */
+ return (u_int)-1;
++ if (proglen < 1 || proglen > BPF_MAXINSNS)
++ return 0;
++
++ /*
++ * Require the current instruction pointer not to overflow for both the
++ * filter program (where the pointer will be dereferenced) and an
++ * immediately following margin (where it will be not). So long as the
++ * margin is large enough to represent the destination of any single
++ * conditional [forward] jump from within the filter program, a single
++ * guard prevents all filter program over-read attempts that result
++ * from the program running out of instructions before a BPF_RET or a
++ * conditional jump directing the interpreter beyond the program end.
++ * Unconditional jumps mean a larger problem space, which the BPF_JA
++ * case below addresses separately.
++ */
++ const struct bpf_insn *pcend = pc + proglen;
++ if (pcend + UINT8_MAX < pc)
++ return 0;
++
+ A = 0;
+ X = 0;
++ const struct bpf_insn *pc0 = pc;
+ --pc;
+ for (;;) {
+ ++pc;
++ if (pc >= pcend)
++ return 0;
+ switch (pc->code) {
+
+ default:
+@@ -241,6 +284,40 @@ DIAG_ON_DEFAULT_ONLY_SWITCH
+ continue;
+
+ case BPF_JMP|BPF_JA:
++ /*
++ * The pointer (pc) decrements and increments in units
++ * of sizeof(struct bpf_insn) == 8 bytes. The number
++ * of units is in the [INT32_MIN, INT32_MAX] interval,
++ * hence the result can point before the beginning or
++ * beyond the end of the filter program and can under-
++ * or overflow; also on 32-bit architectures it can
++ * under- or overflow more than once and can test
++ * negative for underflow, overflow and out-of-range
++ * conditions after under- or overflowing at least
++ * once.
++ *
++ * However, it has been verified above that the program
++ * length is sufficiently small and the pointer does
++ * not wrap within the bounds of the filter program, so
++ * there is a one-to-one correspondence between BPF
++ * program counter values [0, proglen) and all valid
++ * values of the pointer. In other words, after this
++ * unconditional jump the pointer arithmetic result
++ * will be valid iff BPF program counter value will be
++ * valid. For the latter problem the solution is
++ * almost the same as in the validator.
++ *
++ * The main difference is that here the current value
++ * of BPF program counter is not a 32-bit unsigned
++ * variable, but a ptrdiff_t expression, which is
++ * 64-bit signed on 64-bit architectures and 32-bit
++ * signed on 32-bit architectures. However, the cast
++ * to 32-bit unsigned is safe in both cases because:
++ * pc0 <= pc < pc0 + proglen, therefore:
++ * 0 <= pc - pc0 < proglen <= BPF_MAXINSNS < INT32_MAX
++ */
++ if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen)
++ return 0;
+ /*
+ * XXX - we currently implement "ip6 protochain"
+ * with backward jumps, so sign-extend pc->k.
+@@ -394,10 +471,10 @@ DIAG_ON_DEFAULT_ONLY_SWITCH
+ }
+
+ u_int
+-pcapint_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen,
+- u_int buflen)
++pcapint_filter(const struct bpf_insn *pc, const u_int proglen, const u_char *p,
++ u_int wirelen, u_int buflen)
+ {
+- return pcapint_filter_with_aux_data(pc, p, wirelen, buflen, NULL);
++ return pcapint_filter_with_aux_data(pc, proglen, p, wirelen, buflen, NULL);
+ }
+
+ /*
+@@ -417,7 +494,7 @@ pcapint_validate_filter(const struct bpf_insn *f, int len)
+ u_int i, from;
+ const struct bpf_insn *p;
+
+- if (len < 1)
++ if (len < 1 || (u_int)len > BPF_MAXINSNS || f + len < f)
+ return 0;
+
+ for (i = 0; i < (u_int)len; ++i) {
+@@ -483,33 +560,45 @@ pcapint_validate_filter(const struct bpf_insn *f, int len)
+ case BPF_JMP:
+ /*
+ * Check that jumps are within the code block,
+- * and that unconditional branches don't go
+- * backwards as a result of an overflow.
++ * regardless of the direction. libpcap uses
++ * backward jumps to implement the "protochain"
++ * primitive. All offsets that mean a backward
++ * jump in libpcap (whether in-range or not) in
++ * kernel BPF implementations mean out-of-range
++ * or overflow forward jumps -- kernel
++ * implementations must reject that.
++ *
+ * Unconditional branches have a 32-bit offset,
+ * so they could overflow; we check to make
+ * sure they don't. Conditional branches have
+ * an 8-bit offset, and the from address is <=
+- * BPF_MAXINSNS, and we assume that BPF_MAXINSNS
++ * BPF_MAXINSNS, and we know that BPF_MAXINSNS
+ * is sufficiently small that adding 255 to it
+ * won't overflow.
+ *
+ * We know that len is <= BPF_MAXINSNS, and we
+- * assume that BPF_MAXINSNS is < the maximum size
++ * know that BPF_MAXINSNS is < the maximum value
+ * of a u_int, so that i + 1 doesn't overflow.
+- *
+- * For userland, we don't know that the from
+- * or len are <= BPF_MAXINSNS, but we know that
+- * from <= len, and, except on a 64-bit system,
+- * it's unlikely that len, if it truly reflects
+- * the size of the program we've been handed,
+- * will be anywhere near the maximum size of
+- * a u_int. We also don't check for backward
+- * branches, as we currently support them in
+- * userland for the protochain operation.
+ */
+ from = i + 1;
+ switch (BPF_OP(p->code)) {
+ case BPF_JA:
++ /*
++ * So long as both 'from' and bpf_insn.k are
++ * 32-bit unsigned, this check rejects any jump
++ * offset that points outside of the valid BPF
++ * address space of the filter program no
++ * matter whether signed interpretation of the
++ * offset is positive or negative.
++ *
++ * Note that this condition is necessary, but
++ * not sufficient to get correct results from
++ * respective pointer arithmetic in the process
++ * address space. Other necessary conditions
++ * are that BPF_MAXINSNS is correctly defined
++ * and enforced, and that the pointer does not
++ * overflow.
++ */
+ if (from + p->k >= (u_int)len)
+ return 0;
+ break;
+@@ -537,12 +626,14 @@ pcapint_validate_filter(const struct bpf_insn *f, int len)
+
+ /*
+ * Exported because older versions of libpcap exported them.
++ * This function is deprecated and unsafe, use pcap_offline_filter() instead.
+ */
+ u_int
+ bpf_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen,
+ u_int buflen)
+ {
+- return pcapint_filter(pc, p, wirelen, buflen);
++ // The actual length of the filter program is not known.
++ return pcapint_filter(pc, BPF_MAXINSNS, p, wirelen, buflen);
+ }
+
+ int
+diff --git a/dlpisubs.c b/dlpisubs.c
+index d4310de5..19934059 100644
+--- a/dlpisubs.c
++++ b/dlpisubs.c
+@@ -203,7 +203,8 @@ pcap_process_pkts(pcap_t *p, pcap_handler callback, u_char *user,
+ bufp += caplen;
+ #endif
+ ++pd->stat.ps_recv;
+- if (pcapint_filter(p->fcode.bf_insns, pk, origlen, caplen)) {
++ if (pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len,
++ pk, origlen, caplen)) {
+ #ifdef HAVE_SYS_BUFMOD_H
+ pkthdr.ts.tv_sec = sbp->sbh_timestamp.tv_sec;
+ pkthdr.ts.tv_usec = sbp->sbh_timestamp.tv_usec;
+diff --git a/pcap-bpf.c b/pcap-bpf.c
+index 49bb273d..13f83930 100644
+--- a/pcap-bpf.c
++++ b/pcap-bpf.c
+@@ -1372,7 +1372,8 @@ pcap_read_bpf(pcap_t *p, int cnt, pcap_handler callback, u_char *user)
+ #endif
+ */
+ if (pb->filtering_in_kernel ||
+- pcapint_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) {
++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len,
++ datap, bhp->bh_datalen, caplen)) {
+ struct pcap_pkthdr pkthdr;
+ #ifdef BIOCSTSTAMP
+ struct bintime bt;
+diff --git a/pcap-bt-linux.c b/pcap-bt-linux.c
+index 2fc51665..9f464e70 100644
+--- a/pcap-bt-linux.c
++++ b/pcap-bt-linux.c
+@@ -396,7 +396,8 @@ DIAG_ON_SIGN_COMPARE
+ pkth.caplen+=sizeof(pcap_bluetooth_h4_header);
+ pkth.len = pkth.caplen;
+ if (handle->fcode.bf_insns == NULL ||
+- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) {
++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len,
++ pktd, pkth.len, pkth.caplen)) {
+ callback(user, &pkth, pktd);
+ return 1;
+ }
+diff --git a/pcap-bt-monitor-linux.c b/pcap-bt-monitor-linux.c
+index dfba8051..cfe52498 100644
+--- a/pcap-bt-monitor-linux.c
++++ b/pcap-bt-monitor-linux.c
+@@ -153,7 +153,8 @@ DIAG_ON_SIGN_COMPARE
+ bthdr->opcode = htons(hdr.opcode);
+
+ if (handle->fcode.bf_insns == NULL ||
+- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) {
++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len,
++ pktd, pkth.len, pkth.caplen)) {
+ callback(user, &pkth, pktd);
+ return 1;
+ }
+diff --git a/pcap-dag.c b/pcap-dag.c
+index 5ce15dd5..334a970c 100644
+--- a/pcap-dag.c
++++ b/pcap-dag.c
+@@ -666,7 +666,9 @@ dag_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user)
+ caplen = p->snapshot;
+
+ /* Run the packet filter if there is one. */
+- if ((p->fcode.bf_insns == NULL) || pcapint_filter(p->fcode.bf_insns, dp, packet_len, caplen)) {
++ if ((p->fcode.bf_insns == NULL) ||
++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len,
++ dp, packet_len, caplen)) {
+
+ /* convert between timestamp formats */
+ register unsigned long long ts;
+diff --git a/pcap-dbus.c b/pcap-dbus.c
+index d29fb81d..b0f30f6f 100644
+--- a/pcap-dbus.c
++++ b/pcap-dbus.c
+@@ -90,7 +90,8 @@ dbus_read(pcap_t *handle, int max_packets _U_, pcap_handler callback, u_char *us
+
+ gettimeofday(&pkth.ts, NULL);
+ if (handle->fcode.bf_insns == NULL ||
+- pcapint_filter(handle->fcode.bf_insns, (u_char *)raw_msg, pkth.len, pkth.caplen)) {
++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len,
++ (u_char *)raw_msg, pkth.len, pkth.caplen)) {
+ handlep->packets_read++;
+ callback(user, &pkth, (u_char *)raw_msg);
+ count++;
+diff --git a/pcap-dpdk.c b/pcap-dpdk.c
+index c78724e5..4fb8ffea 100644
+--- a/pcap-dpdk.c
++++ b/pcap-dpdk.c
+@@ -405,7 +405,9 @@ static int pcap_dpdk_dispatch(pcap_t *p, int max_cnt, pcap_handler cb, u_char *c
+
+ }
+ if (bp){
+- if (p->fcode.bf_insns==NULL || pcapint_filter(p->fcode.bf_insns, bp, pcap_header.len, pcap_header.caplen)){
++ if (p->fcode.bf_insns==NULL ||
++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len,
++ bp, pcap_header.len, pcap_header.caplen)){
+ cb(cb_arg, &pcap_header, bp);
+ }else{
+ pd->bpf_drop++;
+diff --git a/pcap-haiku.c b/pcap-haiku.c
+index 609f585a..7b994fee 100644
+--- a/pcap-haiku.c
++++ b/pcap-haiku.c
+@@ -112,8 +112,8 @@ pcap_read_haiku(pcap_t* handle, int maxPackets _U_, pcap_handler callback,
+ if (handle->fcode.bf_insns) {
+ // NB: pcapint_filter() takes the wire length and the captured
+ // length, not the snapshot length of the pcap_t handle.
+- if (pcapint_filter(handle->fcode.bf_insns, buffer, wireLength,
+- captureLength) == 0)
++ if (pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len,
++ buffer, wireLength, captureLength) == 0)
+ goto drop;
+ }
+
+diff --git a/pcap-int.h b/pcap-int.h
+index ce0ac698..3d466946 100644
+--- a/pcap-int.h
++++ b/pcap-int.h
+@@ -579,13 +579,15 @@ struct pcap_bpf_aux_data {
+ * Filtering routine that takes the auxiliary data as an additional
+ * argument.
+ */
+-u_int pcapint_filter_with_aux_data(const struct bpf_insn *,
+- const u_char *, u_int, u_int, const struct pcap_bpf_aux_data *);
++u_int pcapint_filter_with_aux_data(const struct bpf_insn *, const u_int,
++ const u_char *, const u_int, const u_int,
++ const struct pcap_bpf_aux_data *);
+
+ /*
+ * Filtering routine that doesn't.
+ */
+-u_int pcapint_filter(const struct bpf_insn *, const u_char *, u_int, u_int);
++u_int pcapint_filter(const struct bpf_insn *, const u_int, const u_char *,
++ u_int, u_int);
+
+ /*
+ * Routine to validate a BPF program.
+diff --git a/pcap-linux.c b/pcap-linux.c
+index 20802e43..7e04a041 100644
+--- a/pcap-linux.c
++++ b/pcap-linux.c
+@@ -4279,6 +4279,7 @@ static int pcap_handle_packet_mmap(
+ aux_data.vlan_tag = tp_vlan_tci & 0x0fff;
+
+ if (pcapint_filter_with_aux_data(handle->fcode.bf_insns,
++ handle->fcode.bf_len,
+ bp,
+ tp_len,
+ snaplen,
+diff --git a/pcap-netfilter-linux.c b/pcap-netfilter-linux.c
+index 344bae47..ade53ea6 100644
+--- a/pcap-netfilter-linux.c
++++ b/pcap-netfilter-linux.c
+@@ -257,8 +257,8 @@ netfilter_read_linux(pcap_t *handle, int max_packets, pcap_handler callback, u_c
+
+ gettimeofday(&pkth.ts, NULL);
+ if (handle->fcode.bf_insns == NULL ||
+- pcapint_filter(handle->fcode.bf_insns, payload, pkth.len, pkth.caplen))
+- {
++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len,
++ payload, pkth.len, pkth.caplen)) {
+ handlep->packets_read++;
+ callback(user, &pkth, payload);
+ count++;
+diff --git a/pcap-netmap.c b/pcap-netmap.c
+index f17f36ca..925f677f 100644
+--- a/pcap-netmap.c
++++ b/pcap-netmap.c
+@@ -79,7 +79,8 @@ pcap_netmap_filter(u_char *arg, struct pcap_pkthdr *h, const u_char *buf)
+ const struct bpf_insn *pc = p->fcode.bf_insns;
+
+ ++pn->rx_pkts;
+- if (pc == NULL || pcapint_filter(pc, buf, h->len, h->caplen))
++ if (pc == NULL ||
++ pcapint_filter(pc, p->fcode.bf_len, buf, h->len, h->caplen))
+ pn->cb(pn->cb_arg, h, buf);
+ }
+
+diff --git a/pcap-npf.c b/pcap-npf.c
+index f638bd80..38e985bd 100644
+--- a/pcap-npf.c
++++ b/pcap-npf.c
+@@ -720,7 +720,8 @@ pcap_read_npf(pcap_t *p, int cnt, pcap_handler callback, u_char *user)
+ */
+ if (pw->filtering_in_kernel ||
+ p->fcode.bf_insns == NULL ||
+- pcapint_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) {
++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len,
++ datap, bhp->bh_datalen, caplen)) {
+ #ifdef ENABLE_REMOTE
+ switch (p->rmt_samp.method) {
+
+diff --git a/pcap-rdmasniff.c b/pcap-rdmasniff.c
+index fd6d6fa6..5f15d4c5 100644
+--- a/pcap-rdmasniff.c
++++ b/pcap-rdmasniff.c
+@@ -170,7 +170,8 @@ rdmasniff_read(pcap_t *handle, int max_packets, pcap_handler callback, u_char *u
+ pktd = (u_char *) handle->buffer + wc.wr_id * RDMASNIFF_RECEIVE_SIZE;
+
+ if (handle->fcode.bf_insns == NULL ||
+- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) {
++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len,
++ pktd, pkth.len, pkth.caplen)) {
+ callback(user, &pkth, pktd);
+ ++priv->packets_recv;
+ ++count;
+diff --git a/pcap-snf.c b/pcap-snf.c
+index d08275ac..8a57eadd 100644
+--- a/pcap-snf.c
++++ b/pcap-snf.c
+@@ -190,7 +190,8 @@ snf_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user)
+ caplen = p->snapshot;
+
+ if ((p->fcode.bf_insns == NULL) ||
+- pcapint_filter(p->fcode.bf_insns, req.pkt_addr, req.length, caplen)) {
++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len,
++ req.pkt_addr, req.length, caplen)) {
+ hdr.ts = snf_timestamp_to_timeval(req.timestamp, p->opt.tstamp_precision);
+ hdr.caplen = caplen;
+ hdr.len = req.length;
+diff --git a/pcap-usb-linux.c b/pcap-usb-linux.c
+index bc39b1db..d219721a 100644
+--- a/pcap-usb-linux.c
++++ b/pcap-usb-linux.c
+@@ -733,8 +733,8 @@ usb_read_linux_bin(pcap_t *handle, int max_packets _U_, pcap_handler callback, u
+ pkth.ts.tv_usec = info.hdr->ts_usec;
+
+ if (handle->fcode.bf_insns == NULL ||
+- pcapint_filter(handle->fcode.bf_insns, handle->buffer,
+- pkth.len, pkth.caplen)) {
++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len,
++ handle->buffer, pkth.len, pkth.caplen)) {
+ handlep->packets_read++;
+ callback(user, &pkth, handle->buffer);
+ return 1;
+@@ -921,8 +921,8 @@ usb_read_linux_mmap(pcap_t *handle, int max_packets, pcap_handler callback, u_ch
+ pkth.ts.tv_usec = hdr->ts_usec;
+
+ if (handle->fcode.bf_insns == NULL ||
+- pcapint_filter(handle->fcode.bf_insns, (u_char*) hdr,
+- pkth.len, pkth.caplen)) {
++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len,
++ (u_char*) hdr, pkth.len, pkth.caplen)) {
+ handlep->packets_read++;
+ callback(user, &pkth, (u_char*) hdr);
+ packets++;
+diff --git a/pcap.c b/pcap.c
+index a076c5fb..6caa052b 100644
+--- a/pcap.c
++++ b/pcap.c
+@@ -4349,7 +4349,7 @@ pcap_offline_filter(const struct bpf_program *fp, const struct pcap_pkthdr *h,
+ const struct bpf_insn *fcode = fp->bf_insns;
+
+ if (fcode != NULL)
+- return (pcapint_filter(fcode, pkt, h->len, h->caplen));
++ return (pcapint_filter(fcode, fp->bf_len, pkt, h->len, h->caplen));
+ else
+ return (0);
+ }
+diff --git a/pcap_offline_filter.3pcap b/pcap_offline_filter.3pcap
+index 94b9a719..c6d62dee 100644
+--- a/pcap_offline_filter.3pcap
++++ b/pcap_offline_filter.3pcap
+@@ -17,7 +17,7 @@
+ .\" WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF
+ .\" MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
+ .\"
+-.TH PCAP_OFFLINE_FILTER 3PCAP "7 April 2014"
++.TH PCAP_OFFLINE_FILTER 3PCAP "12 March 2026"
+ .SH NAME
+ pcap_offline_filter \- check whether a filter matches a packet
+ .SH SYNOPSIS
+@@ -45,10 +45,35 @@ points to the
+ structure for the packet, and
+ .I pkt
+ points to the data in the packet.
++.PP
++In the
++.B \%bpf_program
++structure the
++.B \%bf_insns
++member is either
++.B NULL
++(which means to reject all packets) or points to an array of one or more
++.B \%struct bpf_insn
++elements, in which case the
++.B \%bf_len
++member must be set to the number of elements (this is what
++.BR \%pcap_compile ()
++produces).
++.PP
++The filter program must have been compiled for a link-layer header type
++that matches the packet data; also on Linux the filter must not use
++BPF extensions, see
++.BR \%pcap_compile ()
++for more information.
+ .SH RETURN VALUE
+ .BR pcap_offline_filter ()
+ returns the return value of the filter program. This will be zero if
+ the packet doesn't match the filter and non-zero if the packet matches
+ the filter.
++.SH BACKWARD COMPATIBILITY
++.PP
++In libpcap releases before 1.10.7 this function ignored the provided
++.B \%bf_len
++value.
+ .SH SEE ALSO
+ .BR pcap (3PCAP)
+diff --git a/savefile.c b/savefile.c
+index c711a81c..49ef52b6 100644
+--- a/savefile.c
++++ b/savefile.c
+@@ -685,7 +685,8 @@ pcapint_offline_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user)
+ * and, if it passes, process it.
+ */
+ if ((fcode = p->fcode.bf_insns) == NULL ||
+- pcapint_filter(fcode, data, h.len, h.caplen)) {
++ pcapint_filter(fcode, p->fcode.bf_len,
++ data, h.len, h.caplen)) {
+ (*callback)(user, &h, data);
+ n++; /* count the packet */
+ if (n >= cnt)
diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
index 265c46e3bd0..aa5265a54c7 100644
--- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
+++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
@@ -13,6 +13,7 @@ DEPENDS = "flex-native bison-native"
SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \
file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \
file://01-CVE-2026-0799.patch \
+ file://02-CVE-2026-31912.patch \
"
SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 64/79] libpcap: Fix CVE-2026-31911
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (62 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 63/79] libpcap: Fix CVE-2026-31912 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 65/79] libpcap: Fix CVE-2026-6244 Yoann Congal
` (14 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31911
Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libpcap/libpcap/03-CVE-2026-31911.patch | 45 +++++++++++++++++++
.../libpcap/libpcap_1.10.6.bb | 1 +
2 files changed, 46 insertions(+)
create mode 100644 meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch
diff --git a/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch
new file mode 100644
index 00000000000..1060b3c372a
--- /dev/null
+++ b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch
@@ -0,0 +1,45 @@
+From 0067e8fd1f3caf866da3d95508831389f3b20e11 Mon Sep 17 00:00:00 2001
+From: Denis Ovsienko <denis@ovsienko.info>
+Date: Thu, 30 Jul 2026 13:34:08 +0100
+Subject: [PATCH] CVE-2026-31911: Fail opcodes safely in the BPF interpreter.
+
+This vulnerability has been discovered by FuzzAnything Organization.
+
+The current revision of pcapint_filter_with_aux_data() calls abort() if
+the current instruction opcode is invalid, and assumes this never to be
+the case. This holds for programs that have been generated by libpcap.
+
+However, this does not necessarily hold for programs that come from an
+external source via pcap_offline_filter() or [deprecated] bpf_filter().
+Furthermore, this does not necessarily hold for programs that have been
+validated by libpcap because the current revision of the validator has
+gaps in the checks and accepts a number of invalid opcodes (another
+commit addresses that).
+
+Thus in pcapint_filter_with_aux_data(), when the instruction opcode is
+invalid, just reject the packet.
+
+(backported from commit 4ccb54bf4946d31a248ec93bdbeaabd97fb9d8f7)
+
+(cherry picked from commit a715bcdde830299cba4171514385cb17ec19b6e9)
+
+Notes on backporting to 1.10.6:
+ - The upstream CHANGES/changelog hunk is not backported.
+
+Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9]
+CVE: CVE-2026-31911
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+diff --git a/bpf_filter.c b/bpf_filter.c
+index 4f9adeea..f8b842d6 100644
+--- a/bpf_filter.c
++++ b/bpf_filter.c
+@@ -152,7 +152,7 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen,
+ switch (pc->code) {
+
+ default:
+- abort();
++ return 0;
+ case BPF_RET|BPF_K:
+ return (u_int)pc->k;
+
diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
index aa5265a54c7..da218bd87ba 100644
--- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
+++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
@@ -14,6 +14,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \
file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \
file://01-CVE-2026-0799.patch \
file://02-CVE-2026-31912.patch \
+ file://03-CVE-2026-31911.patch \
"
SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 65/79] libpcap: Fix CVE-2026-6244
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (63 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 64/79] libpcap: Fix CVE-2026-31911 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 66/79] libpcap: Fix CVE-2026-6554 Yoann Congal
` (13 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6244
Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libpcap/libpcap/04-CVE-2026-6244.patch | 50 +++++++++++++++++++
.../libpcap/libpcap_1.10.6.bb | 1 +
2 files changed, 51 insertions(+)
create mode 100644 meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch
diff --git a/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch
new file mode 100644
index 00000000000..b7fec6b554d
--- /dev/null
+++ b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch
@@ -0,0 +1,50 @@
+From e2f4d78f71237c44f730fee11fa0497b756e9d81 Mon Sep 17 00:00:00 2001
+From: Denis Ovsienko <denis@ovsienko.info>
+Date: Thu, 30 Jul 2026 13:34:21 +0100
+Subject: [PATCH] CVE-2026-6244: Avoid division by zero via
+ pcap_offline_filter().
+
+The current revision of pcapint_filter_with_aux_data() for "div x" and
+"mod x" correctly rejects the packet if X is zero, but for "div #k" and
+"mod #k" it assumes that k is never zero. This holds for programs that
+have been generated or validated by libpcap.
+
+However, this does not necessarily hold for programs that come from an
+external source via pcap_offline_filter() or [deprecated] bpf_filter()
+and have not been explicitly validated. If the interpreter executes
+such a program, it can attempt a division by zero, which will typically
+terminate the process via SIGFPE.
+
+To fix this problem, in pcapint_filter_with_aux_data() treat "div #k"
+and "mod #k" the same way as "div x" and "mod x".
+
+(backported from commit 0b2b1ad4a1796513613ff68e9dc09049cc8e0af4)
+
+(cherry picked from commit 98bb921b141aa642faedbf2ac510541c76499a19)
+
+Notes on backporting to 1.10.6:
+ - The upstream CHANGES/changelog hunk is not backported.
+
+Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19]
+CVE: CVE-2026-6244
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+diff --git a/bpf_filter.c b/bpf_filter.c
+index f8b842d6..0178aae5 100644
+--- a/bpf_filter.c
++++ b/bpf_filter.c
+@@ -420,10 +420,14 @@ DIAG_ON_DEFAULT_ONLY_SWITCH
+ continue;
+
+ case BPF_ALU|BPF_DIV|BPF_K:
++ if (pc->k == 0)
++ return 0;
+ A /= pc->k;
+ continue;
+
+ case BPF_ALU|BPF_MOD|BPF_K:
++ if (pc->k == 0)
++ return 0;
+ A %= pc->k;
+ continue;
+
diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
index da218bd87ba..258a15f5bac 100644
--- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
+++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
@@ -15,6 +15,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \
file://01-CVE-2026-0799.patch \
file://02-CVE-2026-31912.patch \
file://03-CVE-2026-31911.patch \
+ file://04-CVE-2026-6244.patch \
"
SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 66/79] libpcap: Fix CVE-2026-6554
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (64 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 65/79] libpcap: Fix CVE-2026-6244 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 67/79] libpcap: Fix CVE-2026-18313 Yoann Congal
` (12 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6554
Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libpcap/libpcap/05-CVE-2026-6554.patch | 94 +++++++++++++++++++
.../libpcap/libpcap_1.10.6.bb | 1 +
2 files changed, 95 insertions(+)
create mode 100644 meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch
diff --git a/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch
new file mode 100644
index 00000000000..208225105d5
--- /dev/null
+++ b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch
@@ -0,0 +1,94 @@
+From ee37e79521d28a04b09f5c37b835ae7955c15e75 Mon Sep 17 00:00:00 2001
+From: Denis Ovsienko <denis@ovsienko.info>
+Date: Thu, 30 Jul 2026 13:34:33 +0100
+Subject: [PATCH] CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter().
+
+This vulnerability has been discovered by Kaixuan LI.
+
+The current revision of pcapint_filter_with_aux_data() assumes that any
+"ja L" instruction in a filter program does not jump to itself or to a
+prior instruction that is guaranteed to reach the same "ja L" again.
+This holds for programs that have been generated by libpcap.
+
+However, this does not necessarily hold for programs that come from an
+external source via pcap_offline_filter() or [deprecated] bpf_filter().
+If the interpreter executes such a program, upon reaching such an
+instruction it will begin looping infinitely.
+
+To mitigate this problem, in pcapint_filter_with_aux_data() enforce a
+hard-coded limit on the number of backward jumps per packet. Ibid., and
+in pcapint_validate_filter() as well, reject the only immediately
+detectable case of an infinite loop.
+
+(backported from commit 63c005c25aeabf1404968add49fc885da3e127e0)
+
+(cherry picked from commit ff3c83475ac303c6b681c52ad0b6e14795a8e0ce)
+
+Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce]
+CVE: CVE-2026-6554
+
+Notes on backporting to 1.10.6:
+ - The stray BPF_S_ANC_* enum removed upstream in 1.10.7 (commit ff47ba55) is
+ still present in 1.10.6, so the new MAX_BACKWARD_JUMPS define is added
+ alongside it instead of replacing it.
+ - The upstream CHANGES/changelog hunk is not backported.
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+diff --git a/bpf_filter.c b/bpf_filter.c
+index 0178aae5..bc6d149f 100644
+--- a/bpf_filter.c
++++ b/bpf_filter.c
+@@ -70,6 +70,8 @@ enum {
+ BPF_S_ANC_VLAN_TAG_PRESENT,
+ };
+
++#define MAX_BACKWARD_JUMPS 64U
++
+ /*
+ * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the
+ * userland interpreter in libpcap is meant to support much longer filter
+@@ -144,6 +146,7 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen,
+ A = 0;
+ X = 0;
+ const struct bpf_insn *pc0 = pc;
++ unsigned backward_jumps = 0;
+ --pc;
+ for (;;) {
+ ++pc;
+@@ -318,6 +321,17 @@ DIAG_ON_DEFAULT_ONLY_SWITCH
+ */
+ if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen)
+ return 0;
++ /*
++ * Terminate the program if this is a non-forward jump
++ * and is:
++ * - a guaranteed infinite loop because it jumps to
++ * itself (exactly the same as in the validator), or
++ * - a backward jump after many enough backward jumps
++ * already made for this packet.
++ */
++ if ((bpf_int32)pc->k < 0 && ((bpf_int32)pc->k == -1 ||
++ backward_jumps++ >= MAX_BACKWARD_JUMPS))
++ return 0;
+ /*
+ * XXX - we currently implement "ip6 protochain"
+ * with backward jumps, so sign-extend pc->k.
+@@ -605,6 +619,17 @@ pcapint_validate_filter(const struct bpf_insn *f, int len)
+ */
+ if (from + p->k >= (u_int)len)
+ return 0;
++ /*
++ * The only type of infinite loop that can be
++ * detected in this function is a "ja L" that
++ * jumps to itself. For this only k == -1
++ * needs to be tested because the check above
++ * has already rejected all other values that
++ * would wrap the pointer equivalently on
++ * 32-bit architectures.
++ */
++ if ((bpf_int32)p->k == -1)
++ return 0;
+ break;
+ case BPF_JEQ:
+ case BPF_JGT:
diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
index 258a15f5bac..6ca75117e17 100644
--- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
+++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
@@ -16,6 +16,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \
file://02-CVE-2026-31912.patch \
file://03-CVE-2026-31911.patch \
file://04-CVE-2026-6244.patch \
+ file://05-CVE-2026-6554.patch \
"
SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 67/79] libpcap: Fix CVE-2026-18313
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (65 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 66/79] libpcap: Fix CVE-2026-6554 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 68/79] libpcap: Fix CVE-2026-18238 Yoann Congal
` (11 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18313
Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libpcap/libpcap/06-CVE-2026-18313.patch | 90 +++++++++++++++++++
.../libpcap/libpcap_1.10.6.bb | 1 +
2 files changed, 91 insertions(+)
create mode 100644 meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch
diff --git a/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch
new file mode 100644
index 00000000000..eae9aaa989b
--- /dev/null
+++ b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch
@@ -0,0 +1,90 @@
+From b039b8b66616852673c21ec5c7e0bad3190eae59 Mon Sep 17 00:00:00 2001
+From: Denis Ovsienko <denis@ovsienko.info>
+Date: Sat, 1 Aug 2026 18:24:48 +0100
+Subject: [PATCH] CVE-2026-18313: Fix a memory leak in rpcapd.
+
+This vulnerability was originally reported publicly, hence no credit is
+given.
+
+daemon_unpackapplyfilter() can allocate a temporary buffer for up to
+RPCAP_BPF_MAXINSNS (8192) BPF instructions (65536 bytes) per each
+received RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message.
+It never frees the memory, so repeated messages from a client will
+eventually leak enough memory on the server to cause problems. This
+holds for all connections that pass the validation and some connections
+that do not.
+
+48 bytes in 1 blocks are definitely lost in loss record 2 of 2
+ at 0x4844818: malloc (vg_replace_malloc.c:446)
+ by 0x111AAB: daemon_unpackapplyfilter (daemon.c:2372)
+ by 0x113279: daemon_msg_startcap_req.constprop.0 (daemon.c:2139)
+ by 0x114808: daemon_serviceloop (daemon.c:901)
+ by 0x115BC7: accept_connection (rpcapd.c:1321)
+ by 0x115BC7: accept_connections (rpcapd.c:1118)
+ by 0x115BC7: main_startup (rpcapd.c:709)
+ by 0x1112BD: main (rpcapd.c:567)
+
+To fix this, after a successful malloc() return exactly once, after the
+free() call.
+
+(backported from commit 26a1c75702b105ac8788014f35f1b5c57fa6043b)
+
+(cherry picked from commit f9775af1a0ec76db60c7213241e6b48f1be10ac7)
+
+Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7]
+CVE: CVE-2026-18313
+
+Notes on backporting to 1.10.6:
+ - The upstream commit was made after the "bogus instructions" -> "invalid
+ instructions" message change (commit 836d0fd0), which is not backported.
+ The 1.10.6 wording ("The filter contains bogus instructions") is therefore
+ kept; only the memory-leak fix (goto free_and_return_status / free()) is
+ applied.
+ - The upstream CHANGES/changelog hunk is not backported.
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+diff --git a/rpcapd/daemon.c b/rpcapd/daemon.c
+index 87274665..b720cc45 100644
+--- a/rpcapd/daemon.c
++++ b/rpcapd/daemon.c
+@@ -2380,14 +2380,8 @@ daemon_unpackapplyfilter(PCAP_SOCKET sockctrl, SSL *ctrl_ssl, struct session *se
+ {
+ status = rpcapd_recv(sockctrl, ctrl_ssl, (char *) &insn,
+ sizeof(struct rpcap_filterbpf_insn), plenp, errmsgbuf);
+- if (status == -1)
+- {
+- return -1;
+- }
+- if (status == -2)
+- {
+- return -2;
+- }
++ if (status == -1 || status == -2)
++ goto free_and_return_status;
+
+ bf_insn->code = ntohs(insn.code);
+ bf_insn->jf = insn.jf;
+@@ -2403,16 +2397,19 @@ daemon_unpackapplyfilter(PCAP_SOCKET sockctrl, SSL *ctrl_ssl, struct session *se
+ if (bpf_validate(bf_prog.bf_insns, bf_prog.bf_len) == 0)
+ {
+ snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "The filter contains bogus instructions");
+- return -2;
++ status = -2;
++ goto free_and_return_status;
+ }
+
+ if (pcap_setfilter(session->fp, &bf_prog))
+ {
+ snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "RPCAP error: %s", pcap_geterr(session->fp));
+- return -2;
++ status = -2;
+ }
+
+- return 0;
++free_and_return_status:
++ free(bf_prog.bf_insns);
++ return status;
+ }
+
+ static int
diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
index 6ca75117e17..859897acc56 100644
--- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
+++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
@@ -17,6 +17,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \
file://03-CVE-2026-31911.patch \
file://04-CVE-2026-6244.patch \
file://05-CVE-2026-6554.patch \
+ file://06-CVE-2026-18313.patch \
"
SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 68/79] libpcap: Fix CVE-2026-18238
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (66 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 67/79] libpcap: Fix CVE-2026-18313 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 69/79] ffmpeg: Fix for CVE-2026-64830 Yoann Congal
` (10 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18238
Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libpcap/libpcap/07-CVE-2026-18238.patch | 222 ++++++++++++++++++
.../libpcap/libpcap_1.10.6.bb | 1 +
2 files changed, 223 insertions(+)
create mode 100644 meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch
diff --git a/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch
new file mode 100644
index 00000000000..d664f5b358b
--- /dev/null
+++ b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch
@@ -0,0 +1,222 @@
+From 5aa9cfee8eb44967dec96199fde879022e4426d4 Mon Sep 17 00:00:00 2001
+From: Denis Ovsienko <denis@ovsienko.info>
+Date: Sat, 8 Aug 2026 00:31:10 +0100
+Subject: [PATCH] CVE-2026-18238: Fix RPCAP_MSG_PACKET validation.
+
+This vulnerability was originally reported publicly, hence no credit is
+given.
+
+When pcap_read_nocb_remote() validates a received message, it does not
+verify that there is a complete RPCAP_MSG_PACKET header in the rpcap
+general payload, also it uses an incorrect value to validate the length
+declared in the RPCAP_MSG_PACKET header. The latter can lead the
+protocol client to over-read the message buffer by 20 bytes, which in at
+least one scenario can cause a SIGSEGV.
+
+Fix this problem, as well as a potential integer overflow in the UDP
+code path on 32-bit architectures. To make message encoding and
+validation easier to follow, re-jig a few variables and update comments.
+
+(backported from commit 2d67e814e8d3791a8b508c359f94688c5669cce9)
+
+(cherry picked from commit b9590d482986d64673712460aae1d48d11fa0473)
+
+Notes on backporting to 1.10.6:
+ - The upstream CHANGES/changelog hunk is not backported.
+
+Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473]
+CVE: CVE-2026-18238
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+diff --git a/pcap-rpcap.c b/pcap-rpcap.c
+index 8f8960b9..b7f54641 100644
+--- a/pcap-rpcap.c
++++ b/pcap-rpcap.c
+@@ -389,10 +389,9 @@ rpcap_deseraddr(struct rpcap_sockaddr *sockaddrin, struct sockaddr **sockaddrout
+ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_char **pkt_data)
+ {
+ struct pcap_rpcap *pr = p->priv; /* structure used when doing a remote live capture */
+- struct rpcap_header *header; /* general header according to the RPCAP format */
+- struct rpcap_pkthdr *net_pkt_header; /* header of the packet, from the message */
++ struct rpcap_header *gen_header; /* rpcap general header */
++ struct rpcap_pkthdr *net_pkt_header; /* RPCAP_MSG_PACKET header */
+ u_char *net_pkt_data; /* packet data from the message */
+- uint32 plen;
+ int retval = 0; /* generic return value */
+ int msglen;
+
+@@ -449,13 +448,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch
+ return 0;
+
+ /*
+- * We have to define 'header' as a pointer to a larger buffer,
+- * because in case of UDP we have to read all the message within a single call
++ * pcap_startcapture_remote() has pointed p->buffer to a buffer large
++ * enough to contain all of the following data at once:
++ *
++ * - a fixed-size rpcap general header
++ * - a fixed-size RPCAP_MSG_PACKET header
++ * - p->snapshot worth of bytes of a captured packet
++ *
++ * This is sufficient for all code paths below.
+ */
+- header = (struct rpcap_header *) p->buffer;
++ gen_header = (struct rpcap_header *)p->buffer;
+ net_pkt_header = (struct rpcap_pkthdr *) ((char *)p->buffer + sizeof(struct rpcap_header));
+ net_pkt_data = (u_char *)p->buffer + sizeof(struct rpcap_header) + sizeof(struct rpcap_pkthdr);
+
++ /*
++ * Step 1: to receive a message that does not immediately look
++ * malformed, consider it as a fixed-size rpcap general header followed
++ * by a variable-size rpcap general payload and require:
++ *
++ * - a complete rpcap general header to land in the buffer, and
++ * - the header to declare an rpcap general payload length that fits
++ * in the buffer after the header, and
++ * - the complete declared payload to land in the buffer after the
++ * header.
++ *
++ * Since this step loosely corresponds to rpcap_process_msg_header(),
++ * which among other things converts rpcap_header.plen to host byte
++ * order, mimic that as well to produce a valid argument for
++ * rpcap_check_msg_ver() later on.
++ */
+ if (pr->rmt_flags & PCAP_OPENFLAG_DATATX_UDP)
+ {
+ /* Read the entire message from the network */
+@@ -471,6 +492,8 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch
+ /* Interrupted receive. */
+ return 0;
+ }
++
++ // Require a complete rpcap general header to be present.
+ if ((size_t)msglen < sizeof(struct rpcap_header))
+ {
+ /*
+@@ -480,8 +503,18 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch
+ "UDP packet message is shorter than an rpcap header");
+ return -1;
+ }
+- plen = ntohl(header->plen);
+- if ((size_t)msglen < sizeof(struct rpcap_header) + plen)
++ gen_header->plen = ntohl(gen_header->plen);
++
++ /*
++ * Validate the rpcap general payload length declared in the
++ * rpcap general header. Use subtraction to avoid an integer
++ * overflow:
++ *
++ * 0 <= gen_header->plen <= UINT32_MAX
++ * sizeof(struct rpcap_header) <= msglen <= p->bufsize
++ * p->bufsize is significantly less than UINT32_MAX
++ */
++ if (gen_header->plen > (size_t)msglen - sizeof(struct rpcap_header))
+ {
+ /*
+ * Message is shorter than the header claims it
+@@ -496,6 +529,7 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch
+ {
+ int status;
+
++ // Receive a complete rpcap general header from the network.
+ if ((size_t)p->cc < sizeof(struct rpcap_header))
+ {
+ /*
+@@ -515,27 +549,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch
+ return 0;
+ }
+ }
++ gen_header->plen = ntohl(gen_header->plen);
+
+ /*
+- * We have the header, so we know how long the
+- * message payload is. The size we should get
+- * is the size of the packet header plus the
+- * size of the payload.
++ * Validate the rpcap general payload length declared in the
++ * rpcap general header. Use subtraction to avoid an integer
++ * overflow:
++ *
++ * 0 <= gen_header->plen <= UINT32_MAX
++ * sizeof(struct rpcap_header) < p->bufsize
++ * p->bufsize is significantly less than UINT32_MAX
+ */
+- plen = ntohl(header->plen);
+- if (plen > p->bufsize - sizeof(struct rpcap_header))
++ if (gen_header->plen > p->bufsize - sizeof(struct rpcap_header))
+ {
+ /*
+ * This is bigger than the largest
+- * record we'd expect. (We do it by
+- * subtracting in order to avoid an
+- * overflow.)
++ * record we'd expect.
+ */
+ snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
+ "Server sent us a message larger than the largest expected packet message");
+ return -1;
+ }
+- status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + plen);
++
++ /*
++ * Receive the declared rpcap general payload from the network.
++ *
++ * p->cc == sizeof(struct rpcap_header)
++ * p->bp == p->buffer + sizeof(struct rpcap_header)
++ */
++ status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + gen_header->plen);
+ if (status == -1)
+ {
+ /* Network error. */
+@@ -558,27 +600,36 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch
+
+ /*
+ * We have the entire message.
+- */
+- header->plen = plen;
+-
+- /*
+- * Did the server specify the version we negotiated?
++ * Step 2: to validate the received message further, require:
++ *
++ * - the rpcap general header to have the correct version and type, and
++ * - the rpcap general payload to be large enough to contain at least a
++ * complete RPCAP_MSG_PACKET header, and
++ * - the RPCAP_MSG_PACKET header to declare an RPCAP_MSG_PACKET payload
++ * (i.e. the captured packet) length that fits in the rpcap general
++ * payload (not the entire buffer) after the RPCAP_MSG_PACKET header.
+ */
+ if (rpcap_check_msg_ver(pr->rmt_sockdata, pr->data_ssl, pr->protocol_version,
+- header, p->errbuf) == -1)
+- {
++ gen_header, p->errbuf) == -1)
++ return 0; /* Return 'no packets received' */
++ if (gen_header->type != RPCAP_MSG_PACKET)
+ return 0; /* Return 'no packets received' */
++ if (gen_header->plen < sizeof(struct rpcap_pkthdr))
++ {
++ snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
++ "Received an incomplete RPCAP_MSG_PACKET header.");
++ return -1;
+ }
+-
+ /*
+- * Is this a RPCAP_MSG_PACKET message?
++ * Validate the RPCAP_MSG_PACKET payload length declared in the
++ * RPCAP_MSG_PACKET header. Use subtraction to avoid an integer
++ * overflow:
++ *
++ * 0 <= ntohl(net_pkt_header->caplen) <= UINT32_MAX
++ * sizeof(struct rpcap_pkthdr) <= gen_header->plen
++ * gen_header->plen is significantly less than UINT32_MAX
+ */
+- if (header->type != RPCAP_MSG_PACKET)
+- {
+- return 0; /* Return 'no packets received' */
+- }
+-
+- if (ntohl(net_pkt_header->caplen) > plen)
++ if (ntohl(net_pkt_header->caplen) > gen_header->plen - sizeof(struct rpcap_pkthdr))
+ {
+ snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
+ "Packet's captured data goes past the end of the received packet message.");
diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
index 859897acc56..2844f4b2a9b 100644
--- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
+++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
@@ -18,6 +18,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \
file://04-CVE-2026-6244.patch \
file://05-CVE-2026-6554.patch \
file://06-CVE-2026-18313.patch \
+ file://07-CVE-2026-18238.patch \
"
SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 69/79] ffmpeg: Fix for CVE-2026-64830
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (67 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 68/79] libpcap: Fix CVE-2026-18238 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 70/79] ffmpeg: Fix for CVE-2026-64831 Yoann Congal
` (9 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-64830
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../ffmpeg/ffmpeg/CVE-2026-64830.patch | 65 +++++++++++++++++++
.../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
2 files changed, 66 insertions(+)
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch
new file mode 100644
index 00000000000..79ed6a45f16
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch
@@ -0,0 +1,65 @@
+From 0ae68ee7e1bc6e2bfde10c78ccc59aa9d99f4d43 Mon Sep 17 00:00:00 2001
+From: Pavel Kohout <disclosure@aisle.com>
+Date: Mon, 29 Jun 2026 23:30:41 +0200
+Subject: [PATCH 1/9] avformat/vobsub: reuse subtitle streams and bound the
+ stream count
+
+Fixes: heap buffer overflow
+Fixes: lqaO5R1BaZGO
+Fixes: dbfe61100b (avformat/vobsub: fix several issues.)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64830
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavformat/mpeg.c | 18 ++++++++++++++++--
+ 1 file changed, 16 insertions(+), 2 deletions(-)
+
+diff --git a/libavformat/mpeg.c b/libavformat/mpeg.c
+index a7a2ef7..1ce4bf9 100644
+--- a/libavformat/mpeg.c
++++ b/libavformat/mpeg.c
+@@ -841,6 +841,20 @@ static int vobsub_read_header(AVFormatContext *s)
+ }
+
+ if (!st || st->id != stream_id) {
++ st = NULL;
++ for (i = 0; i < s->nb_streams; i++) {
++ if (s->streams[i]->id == stream_id) {
++ st = s->streams[i];
++ break;
++ }
++ }
++ }
++ if (!st) {
++ if (s->nb_streams >= FF_ARRAY_ELEMS(vobsub->q)) {
++ av_log(s, AV_LOG_ERROR, "Maximum number of subtitle streams reached\n");
++ ret = AVERROR_INVALIDDATA;
++ goto end;
++ }
+ st = avformat_new_stream(s, NULL);
+ if (!st) {
+ ret = AVERROR(ENOMEM);
+@@ -865,14 +879,14 @@ static int vobsub_read_header(AVFormatContext *s)
+ timestamp = (hh*3600LL + mm*60LL + ss) * 1000LL + ms + delay;
+ timestamp = av_rescale_q(timestamp, av_make_q(1, 1000), st->time_base);
+
+- sub = ff_subtitles_queue_insert(&vobsub->q[s->nb_streams - 1], "", 0, 0);
++ sub = ff_subtitles_queue_insert(&vobsub->q[st->index], "", 0, 0);
+ if (!sub) {
+ ret = AVERROR(ENOMEM);
+ goto end;
+ }
+ sub->pos = pos;
+ sub->pts = timestamp;
+- sub->stream_index = s->nb_streams - 1;
++ sub->stream_index = st->index;
+
+ } else if (!strncmp(line, "alt:", 4)) {
+ const char *p = line + 4;
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8a6eb4eb863..8c1969369b6 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -26,6 +26,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://0001-fftools-resources-Fix-double-build-by-disabling-.d-f.patch \
file://0001-ffbuild-commonmak-Consolidate-pattern-rules-for-comp.patch \
file://0002-ffbuild-common.mak-ensure-target-directories-are-cre.patch \
+ file://CVE-2026-64830.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 70/79] ffmpeg: Fix for CVE-2026-64831
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (68 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 69/79] ffmpeg: Fix for CVE-2026-64830 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 71/79] ffmpeg: Fix for CVE-2026-64832 Yoann Congal
` (8 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-64831
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../ffmpeg/ffmpeg/CVE-2026-64831.patch | 36 +++++++++++++++++++
.../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
2 files changed, 37 insertions(+)
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64831.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64831.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64831.patch
new file mode 100644
index 00000000000..29218b3608f
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64831.patch
@@ -0,0 +1,36 @@
+From 60044ad2b2dbd9a728a1471b0e36eed3157a6ad5 Mon Sep 17 00:00:00 2001
+From: Pavel Kohout <disclosure@aisle.com>
+Date: Tue, 30 Jun 2026 21:55:49 +0200
+Subject: [PATCH] avcodec/vulkan_hevc: reject too many VPS HRD parameter sets
+
+Fixes: stack buffer overflow
+Fixes: tD7Mj0ST7ND3
+Fixes: 82864c21112157951ce91b4430a9018edd02f5ab (vulkan_hevc: use VK_KHR_video_maintenance2 if available)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64831
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavcodec/vulkan_hevc.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+diff --git a/libavcodec/vulkan_hevc.c b/libavcodec/vulkan_hevc.c
+index 5e15c6b931..34676113a9 100644
+--- a/libavcodec/vulkan_hevc.c
++++ b/libavcodec/vulkan_hevc.c
+@@ -875,6 +875,9 @@ static int vk_hevc_end_frame(AVCodecContext *avctx)
+ vksps_p.vcl_hdr, &vksps_p.ptl, &vksps_p.dpbm,
+ &vksps_p.pal, vksps_p.str, &vksps_p.ltr);
+
++ if (sps->vps->vps_num_hrd_parameters > HEVC_MAX_SUB_LAYERS)
++ return AVERROR_INVALIDDATA;
++
+ vkvps_p.sls = vkvps_ps;
+ set_vps(sps->vps, &vkvps, &vkvps_p.ptl, &vkvps_p.dpbm,
+ vkvps_p.hdr, vkvps_p.sls);
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8c1969369b6..02b9cf65a5f 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -27,6 +27,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://0001-ffbuild-commonmak-Consolidate-pattern-rules-for-comp.patch \
file://0002-ffbuild-common.mak-ensure-target-directories-are-cre.patch \
file://CVE-2026-64830.patch \
+ file://CVE-2026-64831.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 71/79] ffmpeg: Fix for CVE-2026-64832
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (69 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 70/79] ffmpeg: Fix for CVE-2026-64831 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 72/79] ffmpeg: Fix for CVE-2026-64833 Yoann Congal
` (7 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-64832
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../ffmpeg/ffmpeg/CVE-2026-64832.patch | 47 +++++++++++++++++++
.../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
2 files changed, 48 insertions(+)
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64832.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64832.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64832.patch
new file mode 100644
index 00000000000..28d6c0343f5
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64832.patch
@@ -0,0 +1,47 @@
+From 55645f03fa9dc2e5ef5f79b875950391e920506b Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Tue, 30 Jun 2026 00:24:07 +0200
+Subject: [PATCH] avcodec/nvdec: don't double free the fdd-owned context on the
+ sep_ref error path
+
+Fixes: double free
+Fixes: rpSz7v3yq2u8
+Fixes: 72982f8cb5dad6252a14226d28128313eed4a5ff (avcodec/nvdec: add support for separate reference frame)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64832
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavcodec/nvdec.c | 6 +-----
+ 1 file changed, 1 insertion(+), 5 deletions(-)
+
+diff --git a/libavcodec/nvdec.c b/libavcodec/nvdec.c
+index 7c29f25718..787a9d7c28 100644
+--- a/libavcodec/nvdec.c
++++ b/libavcodec/nvdec.c
+@@ -628,8 +628,7 @@ int ff_nvdec_start_frame_sep_ref(AVCodecContext *avctx, AVFrame *frame, int has_
+ cf->ref_idx_ref = av_refstruct_pool_get(ctx->decoder_pool);
+ if (!cf->ref_idx_ref) {
+ av_log(avctx, AV_LOG_ERROR, "No decoder surfaces left\n");
+- ret = AVERROR(ENOMEM);
+- goto fail;
++ return AVERROR(ENOMEM);
+ }
+ }
+ cf->ref_idx = *cf->ref_idx_ref;
+@@ -639,9 +638,6 @@ int ff_nvdec_start_frame_sep_ref(AVCodecContext *avctx, AVFrame *frame, int has_
+ }
+
+ return 0;
+-fail:
+- nvdec_fdd_priv_free(cf);
+- return ret;
+ }
+
+ int ff_nvdec_end_frame(AVCodecContext *avctx)
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 02b9cf65a5f..4192b1a5c97 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -28,6 +28,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://0002-ffbuild-common.mak-ensure-target-directories-are-cre.patch \
file://CVE-2026-64830.patch \
file://CVE-2026-64831.patch \
+ file://CVE-2026-64832.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 72/79] ffmpeg: Fix for CVE-2026-64833
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (70 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 71/79] ffmpeg: Fix for CVE-2026-64832 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 73/79] ffmpeg: Fix for CVE-2026-64834 Yoann Congal
` (6 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-64833
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../ffmpeg/ffmpeg/CVE-2026-64833.patch | 36 +++++++++++++++++++
.../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
2 files changed, 37 insertions(+)
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch
new file mode 100644
index 00000000000..407ebf0ece3
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch
@@ -0,0 +1,36 @@
+From 9d412e4715b17404b5e4c6d9f0d2b5c1a100aa74 Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Tue, 30 Jun 2026 00:11:50 +0200
+Subject: [PATCH 2/9] avformat/spdifenc: bound DTS core_size against the packet
+ size in the HD path
+
+Fixes: out of array read
+Fixes: yBSax492UIB9
+Fixes: 482d98f69b2 (spdifenc: IEC 61937 encapsulation of DTS-HD for HDMI)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64833
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavformat/spdifenc.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/libavformat/spdifenc.c b/libavformat/spdifenc.c
+index ab3f73d..16eebda 100644
+--- a/libavformat/spdifenc.c
++++ b/libavformat/spdifenc.c
+@@ -225,7 +225,7 @@ static int spdif_header_dts4(AVFormatContext *s, AVPacket *pkt, int core_size,
+ * (dtshd_fallback == 0) */
+ ctx->dtshd_skip = 1;
+ }
+- if (ctx->dtshd_skip && core_size) {
++ if (ctx->dtshd_skip && core_size && core_size <= pkt->size) {
+ pkt_size = core_size;
+ if (ctx->dtshd_fallback >= 0)
+ --ctx->dtshd_skip;
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 4192b1a5c97..35153b81a99 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -29,6 +29,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://CVE-2026-64830.patch \
file://CVE-2026-64831.patch \
file://CVE-2026-64832.patch \
+ file://CVE-2026-64833.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 73/79] ffmpeg: Fix for CVE-2026-64834
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (71 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 72/79] ffmpeg: Fix for CVE-2026-64833 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:06 ` [OE-core][wrynose 74/79] ffmpeg: Fix for CVE-2026-64835 Yoann Congal
` (5 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-64834
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../ffmpeg/ffmpeg/CVE-2026-64834.patch | 36 +++++++++++++++++++
.../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
2 files changed, 37 insertions(+)
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch
new file mode 100644
index 00000000000..d4a44d293c2
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch
@@ -0,0 +1,36 @@
+From 9ac8fe453e443c3fc07bf85099cc93ca100d302f Mon Sep 17 00:00:00 2001
+From: Pavel Kohout <disclosure@aisle.com>
+Date: Tue, 30 Jun 2026 21:55:16 +0200
+Subject: [PATCH 3/9] avformat/rtpdec_asf: reject ASF objects smaller than
+ their header
+
+Fixes: infinite loop
+Fixes: MzWwJdpZF2Ls
+Fixes: c2f3eec445389d67afc8c699ba23915a20cae51c (Implement RTSP-MS/ASF packet parsing.)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64834
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavformat/rtpdec_asf.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/libavformat/rtpdec_asf.c b/libavformat/rtpdec_asf.c
+index b3b346f..f7fa69e 100644
+--- a/libavformat/rtpdec_asf.c
++++ b/libavformat/rtpdec_asf.c
+@@ -56,6 +56,8 @@ static int rtp_asf_fix_header(uint8_t *buf, int len)
+ uint64_t chunksize = AV_RL64(p + sizeof(ff_asf_guid));
+ int skip = 6 * 8 + 3 * 4 + sizeof(ff_asf_guid) * 2;
+ if (memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) {
++ if (chunksize < sizeof(ff_asf_guid) + 8)
++ return -1;
+ if (chunksize > end - p)
+ return -1;
+ p += chunksize;
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 35153b81a99..c00c3f32b78 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -30,6 +30,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://CVE-2026-64831.patch \
file://CVE-2026-64832.patch \
file://CVE-2026-64833.patch \
+ file://CVE-2026-64834.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 74/79] ffmpeg: Fix for CVE-2026-64835
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (72 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 73/79] ffmpeg: Fix for CVE-2026-64834 Yoann Congal
@ 2026-09-17 22:06 ` Yoann Congal
2026-09-17 22:07 ` [OE-core][wrynose 75/79] ffmpeg: Fix for CVE-2026-65703 Yoann Congal
` (4 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:06 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-64835
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../ffmpeg/ffmpeg/CVE-2026-64835.patch | 45 +++++++++++++++++++
.../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
2 files changed, 46 insertions(+)
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch
new file mode 100644
index 00000000000..735bd1176f0
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch
@@ -0,0 +1,45 @@
+From 99c7dfd80d63bf009a102d3278a9f98b2fe68002 Mon Sep 17 00:00:00 2001
+From: Pavel Kohout <disclosure@aisle.com>
+Date: Mon, 29 Jun 2026 23:46:16 +0200
+Subject: [PATCH 4/9] avcodec/adx: sync decoder channel state on NEW_EXTRADATA
+
+Fixes: out of array access
+Fixes: heaNtmHvklpe
+Fixes: 92396cee602320c714713ca2d93b53684ad57000 (avformat: add CRI AAX demuxer)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64835
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavcodec/adxdec.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/libavcodec/adxdec.c b/libavcodec/adxdec.c
+index 21be6fe..10fd81d 100644
+--- a/libavcodec/adxdec.c
++++ b/libavcodec/adxdec.c
+@@ -172,6 +172,7 @@ static int adx_decode_frame(AVCodecContext *avctx, AVFrame *frame,
+ new_extradata = av_packet_get_side_data(avpkt, AV_PKT_DATA_NEW_EXTRADATA,
+ &new_extradata_size);
+ if (new_extradata && new_extradata_size > 0) {
++ int old_channels = c->channels;
+ int header_size;
+ if ((ret = adx_decode_header(avctx, new_extradata,
+ new_extradata_size, &header_size,
+@@ -180,6 +181,10 @@ static int adx_decode_frame(AVCodecContext *avctx, AVFrame *frame,
+ return AVERROR_INVALIDDATA;
+ }
+
++ c->channels = avctx->ch_layout.nb_channels;
++ c->header_parsed = 1;
++ if (old_channels != c->channels)
++ memset(c->prev, 0, sizeof(c->prev));
+ c->eof = 0;
+ }
+
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index c00c3f32b78..8d3b0dd79e0 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -31,6 +31,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://CVE-2026-64832.patch \
file://CVE-2026-64833.patch \
file://CVE-2026-64834.patch \
+ file://CVE-2026-64835.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 75/79] ffmpeg: Fix for CVE-2026-65703
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (73 preceding siblings ...)
2026-09-17 22:06 ` [OE-core][wrynose 74/79] ffmpeg: Fix for CVE-2026-64835 Yoann Congal
@ 2026-09-17 22:07 ` Yoann Congal
2026-09-17 22:07 ` [OE-core][wrynose 76/79] ffmpeg: Fix for CVE-2026-65704 Yoann Congal
` (3 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:07 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-65703
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../ffmpeg/ffmpeg/CVE-2026-65703.patch | 47 +++++++++++++++++++
.../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
2 files changed, 48 insertions(+)
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch
new file mode 100644
index 00000000000..67c319f17e7
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch
@@ -0,0 +1,47 @@
+From d15f021e27bd2eb4b7aaeb4cc4f2f49ec3435f48 Mon Sep 17 00:00:00 2001
+From: Cloud-LHY <security@clouditera.com>
+Date: Fri, 10 Jul 2026 04:07:04 +0200
+Subject: [PATCH 5/9] avcodec/tdsc: unref the reference frame before
+ reallocating on size change
+
+Fixes: out of array access
+Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py
+Fixes: tdsc_resize_jpeg_oob.avi / tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py
+Fixes: p9xG4xGf9P7H
+Fixes: HQL7a1WgTdHZ
+Found-by: Cloud-LHY / Clouditera Security, Z.ai Security, NSFOCUS
+Found-by: Adrian Junge (vurlo)
+
+CVE: CVE-2026-65703
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavcodec/tdsc.c | 8 ++++++--
+ 1 file changed, 6 insertions(+), 2 deletions(-)
+
+diff --git a/libavcodec/tdsc.c b/libavcodec/tdsc.c
+index 8baf8e9..ecd67da 100644
+--- a/libavcodec/tdsc.c
++++ b/libavcodec/tdsc.c
+@@ -482,11 +482,15 @@ static int tdsc_parse_tdsf(AVCodecContext *avctx, int number_tiles)
+ return ret;
+ init_refframe = 1;
+ }
+- ctx->refframe->width = ctx->width = w;
+- ctx->refframe->height = ctx->height = h;
++ ctx->width = w;
++ ctx->height = h;
+
+ /* Allocate the reference frame if not already done or on size change */
+ if (init_refframe) {
++ av_frame_unref(ctx->refframe);
++ ctx->refframe->format = avctx->pix_fmt;
++ ctx->refframe->width = w;
++ ctx->refframe->height = h;
+ ret = av_frame_get_buffer(ctx->refframe, 0);
+ if (ret < 0)
+ return ret;
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8d3b0dd79e0..8be6b423f75 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -32,6 +32,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://CVE-2026-64833.patch \
file://CVE-2026-64834.patch \
file://CVE-2026-64835.patch \
+ file://CVE-2026-65703.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 76/79] ffmpeg: Fix for CVE-2026-65704
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (74 preceding siblings ...)
2026-09-17 22:07 ` [OE-core][wrynose 75/79] ffmpeg: Fix for CVE-2026-65703 Yoann Congal
@ 2026-09-17 22:07 ` Yoann Congal
2026-09-17 22:07 ` [OE-core][wrynose 77/79] ffmpeg: Fix for CVE-2026-65705 Yoann Congal
` (2 subsequent siblings)
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:07 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-65704
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../ffmpeg/ffmpeg/CVE-2026-65704.patch | 35 +++++++++++++++++++
.../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
2 files changed, 36 insertions(+)
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch
new file mode 100644
index 00000000000..223fd03c334
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch
@@ -0,0 +1,35 @@
+From e6f2209a3ab20ef0489395697a1882e97658b5b9 Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Fri, 10 Jul 2026 04:07:35 +0200
+Subject: [PATCH 6/9] avformat/ty: don't let the Series2 AC3 trim underflow the
+ packet size
+
+Fixes: negative-size-param
+Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py
+Fixes: g0qeE6KvrjZi
+Found-by: Adrian Junge (vurlo)
+
+CVE: CVE-2026-65704
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavformat/ty.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/libavformat/ty.c b/libavformat/ty.c
+index 596e4cc..1f2b6f8 100644
+--- a/libavformat/ty.c
++++ b/libavformat/ty.c
+@@ -577,7 +577,7 @@ static int demux_audio(AVFormatContext *s, TyRecHdr *rec_hdr, AVPacket *pkt)
+ if (ty->audio_type == TIVO_AUDIO_AC3 &&
+ ty->tivo_series == TIVO_SERIES2) {
+ if (ty->ac3_pkt_size + pkt->size > AC3_PKT_LENGTH) {
+- pkt->size -= 2;
++ pkt->size -= FFMIN(pkt->size, 2);
+ ty->ac3_pkt_size = 0;
+ } else {
+ ty->ac3_pkt_size += pkt->size;
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8be6b423f75..82f4b221b75 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -33,6 +33,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://CVE-2026-64834.patch \
file://CVE-2026-64835.patch \
file://CVE-2026-65703.patch \
+ file://CVE-2026-65704.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 77/79] ffmpeg: Fix for CVE-2026-65705
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (75 preceding siblings ...)
2026-09-17 22:07 ` [OE-core][wrynose 76/79] ffmpeg: Fix for CVE-2026-65704 Yoann Congal
@ 2026-09-17 22:07 ` Yoann Congal
2026-09-17 22:07 ` [OE-core][wrynose 78/79] ffmpeg: Fix for CVE-2026-65706 Yoann Congal
2026-09-17 22:07 ` [OE-core][wrynose 79/79] mesa: align x86 mesa config with LLVM graphics Yoann Congal
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:07 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick the patch from [1] and [2], mentioned in PR#23780 [3] which is
referenced in the NVD report [4]
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/24c322fdb232d0a3f3790d544dcb64e5c2138e79
[2] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c
[3] https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780
[4] https://nvd.nist.gov/vuln/detail/cve-2026-65705
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../ffmpeg/ffmpeg/CVE-2026-65705_p1.patch | 68 +++++++++++
.../ffmpeg/ffmpeg/CVE-2026-65705_p2.patch | 115 ++++++++++++++++++
.../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 2 +
3 files changed, 185 insertions(+)
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch
new file mode 100644
index 00000000000..e331cb9646a
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch
@@ -0,0 +1,68 @@
+From f73f6cd9a5f230ce02afbc6a74172400b92b1127 Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Sat, 11 Jul 2026 16:47:28 +0200
+Subject: [PATCH 7/9] avfilter/vf_floodfill: size the point stack for the
+ current frame
+
+Fixes: out of array access
+Fixes: 8aj_floodfill_dynamic_size.pgm / 8aj_generate_floodfill_dynamic_size_pgm.py
+Fixes: 3MleMXjGZvu3
+Found-by: Adrian Junge (vurlo) <adjun37@gmail.com>
+
+CVE: CVE-2026-65705
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/24c322fdb232d0a3f3790d544dcb64e5c2138e79]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavfilter/vf_floodfill.c | 19 ++++++++++++++++---
+ 1 file changed, 16 insertions(+), 3 deletions(-)
+
+diff --git a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c
+index 6d89963..e569d5f 100644
+--- a/libavfilter/vf_floodfill.c
++++ b/libavfilter/vf_floodfill.c
+@@ -41,6 +41,7 @@ typedef struct FloodfillContext {
+ int nb_planes;
+ int back, front;
+ Points *points;
++ unsigned int points_size;
+
+ int (*is_same)(const AVFrame *frame, int x, int y,
+ unsigned s0, unsigned s1, unsigned s2, unsigned s3);
+@@ -271,9 +272,6 @@ static int config_input(AVFilterLink *inlink)
+ }
+
+ s->front = s->back = 0;
+- s->points = av_calloc(inlink->w * inlink->h, 4 * sizeof(Points));
+- if (!s->points)
+- return AVERROR(ENOMEM);
+
+ return 0;
+ }
+@@ -292,8 +290,23 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame)
+ int s3 = s->s[3];
+ const int w = frame->width;
+ const int h = frame->height;
++ size_t nb_points, points_size;
+ int i, ret;
+
++ if (w > UINT16_MAX + 1 || h > UINT16_MAX + 1 ||
++ av_size_mult(w, h, &nb_points) < 0 ||
++ av_size_mult(nb_points, 4 * sizeof(*s->points), &points_size) < 0) {
++ av_frame_free(&frame);
++ return AVERROR(EINVAL);
++ }
++
++ av_fast_malloc(&s->points, &s->points_size, points_size);
++ if (!s->points) {
++ av_frame_free(&frame);
++ return AVERROR(ENOMEM);
++ }
++ s->front = s->back = 0;
++
+ if (is_inside(s->x, s->y, w, h)) {
+ s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3);
+
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch
new file mode 100644
index 00000000000..91a304015f4
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch
@@ -0,0 +1,115 @@
+From 7f99588c7fc27526a2d73dddc91e4cd57a3b401c Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Sun, 12 Jul 2026 03:27:47 +0200
+Subject: [PATCH 8/9] avfilter/vf_floodfill: remove unneeded variables
+
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-65705
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavfilter/vf_floodfill.c | 35 ++++++++++++++++-------------------
+ 1 file changed, 16 insertions(+), 19 deletions(-)
+
+diff --git a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c
+index e569d5f..9bc72e2 100644
+--- a/libavfilter/vf_floodfill.c
++++ b/libavfilter/vf_floodfill.c
+@@ -39,7 +39,6 @@ typedef struct FloodfillContext {
+ int d[4];
+
+ int nb_planes;
+- int back, front;
+ Points *points;
+ unsigned int points_size;
+
+@@ -271,8 +270,6 @@ static int config_input(AVFilterLink *inlink)
+ }
+ }
+
+- s->front = s->back = 0;
+-
+ return 0;
+ }
+
+@@ -292,6 +289,7 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame)
+ const int h = frame->height;
+ size_t nb_points, points_size;
+ int i, ret;
++ int front = 0;
+
+ if (w > UINT16_MAX + 1 || h > UINT16_MAX + 1 ||
+ av_size_mult(w, h, &nb_points) < 0 ||
+@@ -305,7 +303,6 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame)
+ av_frame_free(&frame);
+ return AVERROR(ENOMEM);
+ }
+- s->front = s->back = 0;
+
+ if (is_inside(s->x, s->y, w, h)) {
+ s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3);
+@@ -323,9 +320,9 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame)
+ goto end;
+
+ if (s->is_same(frame, s->x, s->y, s0, s1, s2, s3)) {
+- s->points[s->front].x = s->x;
+- s->points[s->front].y = s->y;
+- s->front++;
++ s->points[front].x = s->x;
++ s->points[front].y = s->y;
++ front++;
+ }
+
+ if (ret = ff_inlink_make_frame_writable(link, &frame)) {
+@@ -333,34 +330,34 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame)
+ return ret;
+ }
+
+- while (s->front > s->back) {
++ while (front > 0) {
+ int x, y;
+
+- s->front--;
+- x = s->points[s->front].x;
+- y = s->points[s->front].y;
++ front--;
++ x = s->points[front].x;
++ y = s->points[front].y;
+
+ if (s->is_same(frame, x, y, s0, s1, s2, s3)) {
+ s->set_pixel(frame, x, y, d0, d1, d2, d3);
+
+ if (is_inside(x + 1, y, w, h)) {
+- s->points[s->front] .x = x + 1;
+- s->points[s->front++].y = y;
++ s->points[front] .x = x + 1;
++ s->points[front++].y = y;
+ }
+
+ if (is_inside(x - 1, y, w, h)) {
+- s->points[s->front] .x = x - 1;
+- s->points[s->front++].y = y;
++ s->points[front] .x = x - 1;
++ s->points[front++].y = y;
+ }
+
+ if (is_inside(x, y + 1, w, h)) {
+- s->points[s->front] .x = x;
+- s->points[s->front++].y = y + 1;
++ s->points[front] .x = x;
++ s->points[front++].y = y + 1;
+ }
+
+ if (is_inside(x, y - 1, w, h)) {
+- s->points[s->front] .x = x;
+- s->points[s->front++].y = y - 1;
++ s->points[front] .x = x;
++ s->points[front++].y = y - 1;
+ }
+ }
+ }
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 82f4b221b75..e39961c6499 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -34,6 +34,8 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://CVE-2026-64835.patch \
file://CVE-2026-65703.patch \
file://CVE-2026-65704.patch \
+ file://CVE-2026-65705_p1.patch \
+ file://CVE-2026-65705_p2.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 78/79] ffmpeg: Fix for CVE-2026-65706
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (76 preceding siblings ...)
2026-09-17 22:07 ` [OE-core][wrynose 77/79] ffmpeg: Fix for CVE-2026-65705 Yoann Congal
@ 2026-09-17 22:07 ` Yoann Congal
2026-09-17 22:07 ` [OE-core][wrynose 79/79] mesa: align x86 mesa config with LLVM graphics Yoann Congal
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:07 UTC (permalink / raw)
To: openembedded-core
From: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-65706
Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../ffmpeg/ffmpeg/CVE-2026-65706.patch | 52 +++++++++++++++++++
.../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
2 files changed, 53 insertions(+)
create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch
new file mode 100644
index 00000000000..7311ed71c0c
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch
@@ -0,0 +1,52 @@
+From 825f9e837f88c0c6983b5ccb70f91a32e9168f3c Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Sat, 11 Jul 2026 16:46:39 +0200
+Subject: [PATCH 9/9] avfilter/vf_swaprect: size the temp row buffer for the
+ widest plane
+
+Fixes: out of array access
+Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py
+Fixes: VRAXYvKtmKa8
+Found-by: Adrian Junge (vurlo) <adjun37@gmail.com>
+
+CVE: CVE-2026-65706
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavfilter/vf_swaprect.c | 12 +++++++++++-
+ 1 file changed, 11 insertions(+), 1 deletion(-)
+
+diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c
+index 5d93f51..fe007ee 100644
+--- a/libavfilter/vf_swaprect.c
++++ b/libavfilter/vf_swaprect.c
+@@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink)
+ {
+ AVFilterContext *ctx = inlink->dst;
+ SwapRectContext *s = ctx->priv;
++ int size = 0;
+
+ if (!s->w || !s->h ||
+ !s->x1 || !s->y1 ||
+@@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink)
+ av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc);
+ s->nb_planes = av_pix_fmt_count_planes(inlink->format);
+
+- s->temp = av_malloc_array(inlink->w, s->pixsteps[0]);
++ for (int p = 0; p < s->nb_planes; p++) {
++ int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0;
++ int width = AV_CEIL_RSHIFT(inlink->w, shift);
++
++ if (width > INT_MAX / s->pixsteps[p])
++ return AVERROR(EINVAL);
++ size = FFMAX(size, width * s->pixsteps[p]);
++ }
++
++ s->temp = av_malloc(size);
+ if (!s->temp)
+ return AVERROR(ENOMEM);
+
+--
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index e39961c6499..48ece247600 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -36,6 +36,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://CVE-2026-65704.patch \
file://CVE-2026-65705_p1.patch \
file://CVE-2026-65705_p2.patch \
+ file://CVE-2026-65706.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
^ permalink raw reply related [flat|nested] 80+ messages in thread* [OE-core][wrynose 79/79] mesa: align x86 mesa config with LLVM graphics
2026-09-17 22:05 [OE-core][wrynose 00/79] Patch review Yoann Congal
` (77 preceding siblings ...)
2026-09-17 22:07 ` [OE-core][wrynose 78/79] ffmpeg: Fix for CVE-2026-65706 Yoann Congal
@ 2026-09-17 22:07 ` Yoann Congal
78 siblings, 0 replies; 80+ messages in thread
From: Yoann Congal @ 2026-09-17 22:07 UTC (permalink / raw)
To: openembedded-core
From: AshishKumar Mishra <emailaddress.ashish@gmail.com>
This change makes the x86 and native mesa PACKAGECONFIG appends conditional
on the same DISTRO_FEATURES check used by LLVM.
As a result, graphics-related Mesa and LLVM options are only added when the
distro explicitly enables a graphics stack, while leaving non-graphics
minimal images unchanged.
(cherry picked from commit 2cf81caa69474c5ec2397ca37622c86519791d44)
Signed-off-by: AshishKumar Mishra <emailaddress.ashish@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-graphics/mesa/mesa.bb | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/meta/recipes-graphics/mesa/mesa.bb b/meta/recipes-graphics/mesa/mesa.bb
index 66c8f9c3720..a646c16af75 100644
--- a/meta/recipes-graphics/mesa/mesa.bb
+++ b/meta/recipes-graphics/mesa/mesa.bb
@@ -13,10 +13,10 @@ PACKAGECONFIG = " \
zlib \
"
-PACKAGECONFIG:append:x86 = " libclc gallium-llvm intel amd nouveau svga"
-PACKAGECONFIG:append:x86-64 = " libclc gallium-llvm intel amd nouveau svga"
-PACKAGECONFIG:append:i686 = " libclc gallium-llvm intel amd nouveau svga"
-PACKAGECONFIG:append:class-native = " libclc gallium-llvm amd nouveau svga"
+PACKAGECONFIG:append:x86 = "${@bb.utils.contains_any('DISTRO_FEATURES', 'opengl opencl vulkan', ' libclc gallium-llvm intel amd nouveau svga', '', d)}"
+PACKAGECONFIG:append:x86-64 = "${@bb.utils.contains_any('DISTRO_FEATURES', 'opengl opencl vulkan', ' libclc gallium-llvm intel amd nouveau svga', '', d)}"
+PACKAGECONFIG:append:i686 = "${@bb.utils.contains_any('DISTRO_FEATURES', 'opengl opencl vulkan', ' libclc gallium-llvm intel amd nouveau svga', '', d)}"
+PACKAGECONFIG:append:class-native = "${@bb.utils.contains_any('DISTRO_FEATURES', 'opengl opencl vulkan', ' libclc gallium-llvm amd nouveau svga', '', d)}"
GLPROVIDES = " \
${@bb.utils.contains('PACKAGECONFIG', 'opengl', 'virtual/libgl', '', d)} \
^ permalink raw reply related [flat|nested] 80+ messages in thread