Commit Graph

76322 Commits

Author SHA1 Message Date
Hetvi Thakar
00e6a3df8c patch: Fix CVE-2026-56288
This patch applies the upstream fix referenced by NVD in [2], using
the commit shown in [1].

[1] https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=e6d6a4e021660679d7fc9150f981d4920f722313
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-56288

(From OE-Core rev: 1b1e13055b4eed838e1411d91dea46de08e1d72f)

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit a30cd69993f9f48d5cf55e57181e49171f0a1b7a)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Hetvi Thakar
f03efa1107 patch: Fix CVE-2026-56289
This patch applies the upstream fix referenced by NVD in [2], using
the commit shown in [1].

[1] https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-56289

(From OE-Core rev: b1540647185015c99fbf421d889547a6c10e7e29)

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 48c1aa91e829a87c398e8c012cde45cd8c1aab0a)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Siddharth Doshi
dc97ef25ad vim: Security Fix for CVE-2026-57456
Picking patch as per [1], and same patch is mentioned in [2]

References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57456
[2] https://security-tracker.debian.org/tracker/CVE-2026-57456

(From OE-Core rev: 146c6244fdc0647f6c24b92cc8410da02645ee96)

Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Siddharth Doshi
b3092dd954 vim: Security Fix for CVE-2026-59858
Picking patch as per [1], and same patch is mentioned in [2]

References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858
[2] https://security-tracker.debian.org/tracker/CVE-2026-59858

(From OE-Core rev: 7a9e6b91121683b4694d11138f148bfdd3e6f97a)

Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Siddharth Doshi
4d706214f7 vim: Security Fix for CVE-2026-59857
Picking patch as per [1], and same patch is mentioned in [2]

References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59857
[2] https://security-tracker.debian.org/tracker/CVE-2026-59857

(From OE-Core rev: 65c4b003cddf3a2489118a04c3caec37c8256df7)

Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Siddharth Doshi
7d5a2907dd vim: Security Fix for CVE-2026-59856
Picking patch as per [1], and same patch is mentioned in [2]

References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59856
[2] https://security-tracker.debian.org/tracker/CVE-2026-59856

(From OE-Core rev: fbffe073ee8694f5c69e2f84aee356d5d02238f5)

Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Siddharth Doshi
7a38ffe737 vim: Security Fix for CVE-2026-57455
Picking patch as per [1], and same patch is mentioned in [2]

References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57455
[2] https://security-tracker.debian.org/tracker/CVE-2026-57455

(From OE-Core rev: 91c8229fe73a22fdd07cec3db56fee2f281f1942)

Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Siddharth Doshi
d4b6cf3a61 vim: Security Fix for CVE-2026-57452
Picking patch as per [1], and same patch is mentioned in [2]

References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57452
[2] https://security-tracker.debian.org/tracker/CVE-2026-57452

(From OE-Core rev: 140b752df903df36a10ffeb1f2bca7b2e3bb8a06)

Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Siddharth Doshi
68da6e5e76 vim: Security Fix for CVE-2026-55895
Picking patch as per [1], and same patch is mentioned in [2]

References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-55895
[2] https://security-tracker.debian.org/tracker/CVE-2026-55895

(From OE-Core rev: 87b2def5858ea51650b1e0381ed104d5670c50b1)

Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Siddharth Doshi
ce0d6f7939 vim: Security Fix for CVE-2026-55892
Picking patch as per [1], and same patch is mentioned in [2]

References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-55892
[2] https://security-tracker.debian.org/tracker/CVE-2026-55892

(From OE-Core rev: df7fb45b185ad3fd3b339ee25ce9dad041741f25)

Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Siddharth Doshi
4957a62a52 vim: Security Fix for CVE-2026-55693
Picking patch as per [1], and same patch is mentioned in [2]

References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-55693
[2] https://security-tracker.debian.org/tracker/CVE-2026-55693

(From OE-Core rev: f4d6729cf38708effd445aa739bfd34d3adda3d0)

Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Hetvi Thakar
56161d9fc4 wget: Fix CVE-2026-58472
Apply the upstream fix referenced in [2] using the commit
listed in [1].
Also include the upstream follow-up commit [3], which fixes
encoded entity length handling and adds regression tests.

[1] dd692d9cea
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58472
[3] f76978a51b

(From OE-Core rev: c359e2d4f41b352b26004f3f9590bef29815b3a1)

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Hetvi Thakar
23aff30de0 wget: Fix CVE-2026-58471
This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].

[1] c2640fe517
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58471

(From OE-Core rev: e8a20e6c7f6b2fc06b1ef0fabf63ed5fc349f1ac)

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Hetvi Thakar
a3df9d6274 wget: Fix CVE-2026-58469
This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].

It also includes the upstream follow-up fixes referenced in [3]
and [4]. These correct the trailing whitespace check introduced
by the original fix and add the required <ctype.h> include for
isspace().

[1] 37a40fcb45
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58469
[3] 7b1cdecc49
[4] 82d945ff5d

(From OE-Core rev: 9b76cb0b22f9a0ec2877ac69ab4007f2cd2178e5)

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Jaipaul Cheernam
1a7b2e6b68 perl: fix CVE-2025-40909
This patch applies the upstream fix as referenced in [1], using the
commit shown in [2].

[1] https://nvd.nist.gov/vuln/detail/CVE-2025-40909
[2] 918bfff86c

(From OE-Core rev: 4a210e907972f476c87fbfefe502735abd230dce)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: CVE-2025-40909.patch is not merged on a main branch but was
provided by upstream to facilitate backport (Thanks!)
https://github.com/Perl/perl5/issues/23010#issuecomment-2919448987
]
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Jaipaul Cheernam
68cfa8f4db perl: fix CVE-2026-57432
This patch applies the upstream fix as referenced in [1], using the
commits shown in [2] and [3].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57432
[2] 5f7eb6bbbe
[3] 40754edc72

(From OE-Core rev: 93fbbdc19eea157c4c9b040291481c4f778ab6db)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Jaipaul Cheernam
f4fecd5a7b perl: fix CVE-2026-13221
This patch applies the upstream fix as referenced in [1], using the
commit shown in [2].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-13221
[2] 03f74bbbd3

(From OE-Core rev: dd5aee19c57a18b1c403496190e832234afc3b4b)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Peter Marko
1045aca106 gnutls: set status for CVE-2026-1584
Set status per [1].

[1] https://security-tracker.debian.org/tracker/CVE-2026-1584

(From OE-Core rev: a04716f2209d4d374d7e42388776917fb4179adc)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Peter Marko
bf5d6de552 libarchive: patch CVE-2026-5745
Pick patch per [1].

[1] https://security-tracker.debian.org/tracker/CVE-2026-5745

(From OE-Core rev: f35b64a303e5c3641a76576e69fe921a4b6166f9)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Peter Marko
fd0ffc6666 libarchive: handle CVE-2026-5121
Cherry-pick patch for this CVE mentioned in [1].

Since the actual code change is already included in previous patch for
CVE-2026-4426, add reference to CVE-2026-5121 to that patch and keep the
remaining part (test) as CVE-2026-5121-02.patch.

[1] https://security-tracker.debian.org/tracker/CVE-2026-5121

(From OE-Core rev: 608a151948db9652b0e7032863bba1ed022a00aa)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Peter Marko
88843705b1 systemd: upgrade 255.21 -> 255.22
Full changelog (36 commits):
* https://github.com/systemd/systemd-stable/compare/v255.21...v255.22

(From OE-Core rev: 846292594d7513e0ffbec5e0481084844505b51c)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: fixed changelog URL]
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Peter Marko
72055be747 python3: upgrade 3.12.13 -> 3.12.14
This is a security release of Python 3.12
Release information: [1]

* drop CVE patches included in this release
* refresh all remaining patches via devtool
* remove some tab style in SRC_URI.
* add CVE_STATUS entries for CVEs fixed in this release but still
  reported as Unpatched by cve-check (including 2 fixed already in
  previous release)

[1] https://www.python.org/downloads/release/python-31214/

(From OE-Core rev: 57549d561886972b733952a4e4077cd8889d12ed)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Emily Vekariya
d78b160b6c python3-pyasn1: Fix CVE-2026-59884
The BER decoder shared by the CER and DER codecs parses long-form tags by
accumulating continuation octets without an upper bound on the tag ID size.
A crafted input can force construction of an arbitrarily large integer with
CPU cost growing quadratically, and can trigger unhandled ValueError
exceptions in the Python 3.11+ error formatting paths. Any application
decoding untrusted BER, CER, or DER input is affected.

scarthgap ships pyasn1 0.5.1, which is affected as the issue is present in
all versions before 0.6.4.

Pick the upstream patch [1] as mentioned in [2].

[1] 628e36ecbb
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59884

(From OE-Core rev: 75ff4b187cf1b5e4e874cab8273ea84377b3c873)

Signed-off-by: Emily Vekariya <evekariy@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Emily Vekariya
a2d922f58f python3-pyasn1: Fix CVE-2026-59886
The univ.Real type converts its mantissa, base, and exponent to a Python
float using exact big-integer exponentiation. A BER, CER, or DER encoded
REAL value only a few bytes long can carry a very large exponent, causing
float conversion through prettyPrint(), str(), comparison, arithmetic,
int(), or an explicit float() call to consume excessive CPU and memory and
hang applications that decode untrusted ASN.1 data and then print, log, or
compare the decoded objects.

scarthgap ships pyasn1 0.5.1, which is affected as the issue is present in
all versions before 0.6.4.

Pick the upstream patch [1] as mentioned in [2].

[1] e60c691cb9
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59886

(From OE-Core rev: 24991f7383dbe229a696ad209ae7d58115a051a1)

Signed-off-by: Emily Vekariya <evekariy@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Jaipaul Cheernam
3dcbd1b54b systemd: Fix CVE-2026-29111
Backport patches from upstream systemd to fix CVE-2026-29111, where
systemd (as PID 1) hits an assert and freezes execution when an
unprivileged IPC API call is made with spurious data.

Pick patches from [1], [2], [3] and [4] as referenced in [5].

Note: As scarthgap is using 255 version picked fixes from 257

[1] 20021e7686
[2] 7ac3220213
[3] 2116700657
[4] 54588d2ded
[5] https://security-tracker.debian.org/tracker/CVE-2026-29111

(From OE-Core rev: b229b0b6c4004c6588e684d790343df249cedd57)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Hemanth Kumar M D
83b4945732 glibc: fix CVE-2026-5435
resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435)

Specifically, CERT, TKEY, TSIG, OPT.  This removes the buggy
implementations of TSIG, fixing bug 34033, and partially
fixing bug 34069.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-5435
[2] https://sourceware.org/bugzilla/show_bug.cgi?id=34033
[3] https://sourceware.org/git/?p=glibc.git;a=commit;h=ca44a6609c29a683b03575fa035c6d17aa591e72

(From OE-Core rev: 336e429b4d0048964cf883c187438ca7c5aca2ea)

Signed-off-by: Hemanth Kumar M D <Hemanth.KumarMD@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: This patch will change output of a debug and deprecated function.
     Upstream chose to remove the vulnerable implementation instead of
     fixing it.
     See: https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0011
]
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Martin Jansa
ca1fb3108c socat: fix native build on host with newer glibc
Fixes:
../socat-1.8.0.0/filan.c: In function ?printtime?:
../socat-1.8.0.0/filan.c:1065:46: error: assignment of read-only location ?*(const char *)strchr(s, 10)?
 1065 |       if (strchr(s, '\n'))  *strchr(s, '\n') = '\0';
      |                                              ^

(From OE-Core rev: 0cd52c822a9929399fe8840955ff451216182f36)

Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-04 10:39:10 +01:00
Richard Purdie
69ae79bf5a build-appliance-image: Update to scarthgap head revision
(From OE-Core rev: 310eec2cb646d7d1a3ca99bad7e37495bb418a0d)

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:43 +01:00
Vijay Anusuri
7759e1bf21 rpcbind: Fix CVE-2026-16277
Pick patch according to [2]

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-16277
[2] https://security-tracker.debian.org/tracker/CVE-2026-16277

(From OE-Core rev: b7007d82eec734bab6760ae325645ae5b199e384)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Peter Marko
f4caf6cd58 bison: patch CVE-2026-56389
Pick patch mentioned in NVD CVE report.

(From OE-Core rev: 1f3e800a68de0c053e95eed781fbaab567912c06)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 6c99410bd7f0bc4e2ed41ef5afe7d6b5fcb99837)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Ross Burton
c80225aad3 bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES
We export GIT_CEILING_DIRECTORIES=WORKDIR to ensure that git calls
inside the builds don't find oe-core when they're meant to be looking
for the git repository of the source code.

However, this breaks for recipes that use work-shared (such as llvm), as
their working directory is outside of WORKDIR.

Solve this by adding TMPDIR to the list as a final catch, but keeping
WORKDIR first so that git will stop sooner in the general case.

This solves reproduciblity problems in LLVM, where for example lld's
version string would contain the URL and commit hash of the poky repo
being built.

(From OE-Core rev: b2258129ecabc6a85fe9dc48f580e881d27a68c0)

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit f42f0185bd00e68ecc86a930487f21fc86214cfa)
Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
[fatho: edit commit message by adding "cherry picked from"]
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Etienne Cordonnier
5b35d2e634 curl: fix CVE-2025-10148 backport for websockets on 8.7.1
The original backport applied upstream's CURLcode return path into
ssize_t ws_enc_write_head(), which uses an undeclared result and is
invalid for curl 8.7.1's API. Builds with --enable-websockets fail.

Adapt Curl_rand() error handling to set *err and return -1.

AI-Generated: Claude Sonnet 4.6
(From OE-Core rev: 152c139de6b1ad00d904b5fd16b4abc9852459a4)

Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Deepak Rathore
1d390a4e04 glib-2.0: fix CVE-2026-58015
This patch applies the upstream glib-2-88 stable backport chain for
CVE-2026-58015. The issue is in the D-Bus SHA-1 authentication
mechanism, where a malicious peer could provide an unchecked cookie
context and cause the client to access unintended files while resolving
the cookie challenge.

Backport the upstream GLib fix chain from the glib-2-88 stable branch:
- db9c8fae398b validates cookie_context before keyring lookup. This is
the primary security fix for CVE-2026-58015 [1].
- c0531125344b tightens cookie ID parsing so empty, negative, and
out-of-range values are rejected. This hardens the same SHA-1 cookie
challenge parser and is covered by the upstream regression test [2].
- 060aea67de75 exposes the private client reject-reason vfunc. This is
test-support plumbing required by the upstream regression test [3].
- 091930196229 adds the upstream regression test for SHA-1 cookie
challenge parsing [4].

Add dbus-native to PACKAGECONFIG[tests] so Meson can find dbus-daemon
when building the new installed D-Bus regression test for ptest. This is
kept as a native-only test dependency to avoid adding a target dbus
dependency to glib.

[1] db9c8fae39
[2] c053112534
[3] 060aea67de
[4] 0919301962
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-58015

(From OE-Core rev: b6b82e3c1442b658bd4c1689e09792c9a3a96947)

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Adarsh Jagadish Kamini
8cf593c04e libssh2: fix CVE-2026-58050
Backport patch to fix CVE-2026-58050.

References:
  https://nvd.nist.gov/vuln/detail/CVE-2026-58050

Upstream fix:
  3449752592

(From OE-Core rev: 4b86de3333748d41785365fc62f6afabb454b62b)

Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Jaipaul Cheernam
2a1e2de813 binutils: fix CVE-2026-18220
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-18220
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=114e3aae2b7e34057c8909301eaf78c15687e8e5

Test results:
  binutils-cross-testsuite 2.42 (x86_64-oe-linux):

  Before:
  binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

  After:
  binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=114e3aae2b7e34057c8909301eaf78c15687e8e5]
(From OE-Core rev: c9f3a2e7641af10ef9c43359a805191356fe0d67)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Jaipaul Cheernam
5c215d3c91 binutils: fix CVE-2026-15003
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-15003
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c

Test results:
  binutils-cross-testsuite 2.42 (x86_64-oe-linux):

  Before:
  binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

  After:
  binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c]
(From OE-Core rev: b4675cb889edb4de1f53d9c6c883d0d5d622e49b)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Jaipaul Cheernam
d93c5f476f binutils: fix CVE-2025-8224
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-8224
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=db856d41004301b3a56438efd957ef5cabb91530

[Adapted for binutils 2.42: only the shstrtabsize overflow check in
bfd_elf_get_str_section applies. The second upstream hunk (DT_STRTAB)
does not apply as 2.42 already unconditionally null-terminates the
dynamic string table.]

Test results:
  binutils-cross-testsuite 2.42 (x86_64-oe-linux):

  Before:
  binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

  After:
  binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=db856d41004301b3a56438efd957ef5cabb91530]
(From OE-Core rev: cadb858fcabe3fae57fc7efc5092c1574a50dd3a)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Jaipaul Cheernam
e0d7b71bd7 binutils: fix CVE-2025-1147
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-1147
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=7be4186c22f89a87fff048c28910f5d26a0f61ce

Test results:
  binutils-cross-testsuite 2.42 (x86_64-oe-linux):

  Before:
  binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

  After:
  binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported (+2 new passes from nm --ifunc-chars=-- tests)
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported

Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=7be4186c22f89a87fff048c28910f5d26a0f61ce]
(From OE-Core rev: 188efbb43453920a5c4f6c246dd881e7ab67f319)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Deepak Rathore
04d688a25e nghttp2: set status for CVE-2026-58055
CVE-2026-58055 affects the nghttpx proxy when forwarding HTTP/1.1
Upgrade requests with a Content-Length header and body.

The default recipe does not build nghttpx. Add a conditional
CVE_STATUS entry so the CVE remains unpatched if app support is
enabled, while default builds are marked not-applicable-config.

References:
https://nvd.nist.gov/vuln/detail/CVE-2026-58055

(From OE-Core rev: aef685e73f971bd631f67cf88200c7ebf449d21c)

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-08-28 09:52:24 +01:00
Paul Barker
64e69ed237 build-appliance-image: Update to scarthgap head revision
Bump b-a SRCREV again to pull in docs changes.

(From OE-Core rev: 70dc15941dd33270a92d1001174efb3093e79bdf)

Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:30:56 +01:00
Quentin Schulz
b70aeb3af5 README: update instructions for installing vale and sphinx-lint
pip install won't work on recent Debian distros (and Debian-based ones
I'm assuming as well) and will suggest using pipx instead.

In any case, pip and pipx aren't actually that user-friendly to us for
the simple reason the instructions to build the documentation, c.f.
documentation/tools/host_packages_scripts/pip3_docs.sh, make use of a
virtual environment which doesn't have access to the host system's
Python modules (missing --system-site-packages). So you would need to
chose between building the docs and running vale/sphinx-lint but not
both at the same time.

Instead, update the instructions to use pipenv for stylecheck and
sphinx-lint make targets such that there's a setup in which one can
build the docs AND run those commands without doing some back and forth
between venvs or host packages and the venv.

Reported-by: Robert P. J. Day <rpjday@crashcourse.ca>
Closes: https://lore.kernel.org/yocto-docs/959e65b6-e7eb-bcc3-992f-bed7276c8449@crashcourse.ca/
(From yocto-docs rev: fe46d5de41930a2762a9ad2543d50e0f4e10463b)

Signed-off-by: Quentin Schulz <quentin.schulz@cherry.de>
Link: https://patch.msgid.link/20260821-pipenv-vale-sphinx-lint-v1-1-f108b7e3e739@cherry.de
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 9955b0f099b6b42a9750f0d544944a2d8e5a39b2)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:26:37 +01:00
Antonin Godard
23ecb8d810 ref-manual/variables.rst: document the PACKAGEFUNCS variable
Added by commit 4b46c1f6e8 ("Initial population") in OE-Core. This
completes the variables used during do_package, as
PACKAGE_PREPROCESS_FUNCS and PACKAGESPLITFUNCS are already documented.

Link: https://patch.msgid.link/20260818-packagefuncs-v1-2-1f26764cbdd3@bootlin.com
(From yocto-docs rev: c7082a42f69f99e277864f319c1e8a71b7c62ada)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit c3e8c602c60bf78123d6a05b83346235abf7f233)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:26:37 +01:00
Antonin Godard
4f226dfe73 ref-manual/variables.rst: document the PACKAGE_NO_LOCALE variable
Added by commit 4b46c1f6e8 ("Initial population") in OE-Core (2005!).

Link: https://patch.msgid.link/20260818-packagefuncs-v1-1-1f26764cbdd3@bootlin.com
(From yocto-docs rev: 1cf267bd4dbd0c0ffbdc5a36dd608dae731b6640)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 6d69a4744a4d1cfa45dafcf5af28658cafe30a1e)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:26:37 +01:00
Antonin Godard
779318a316 index.rst: show the intro paragraph only for html-based docs
The current non-HTML-based documents we support is the PDF format. For
this format, this intro paragraph is placed right after the table of
contents, which is odd and breaks the flow of the document. Show this
paragraph only in HTML-based document, which includes the HTML and ePUB
formats.

Link: https://patch.msgid.link/20260818-intros-only-in-html-v1-1-4fe4c54655bf@bootlin.com
(From yocto-docs rev: f24fed24c0893074d5990b15436229d9957d4038)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 8e70193dc4c6271e0226cdda7110cf60347f0f51)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:26:37 +01:00
Daiane Angolini
ac4a16fccc docs-wide: fix manual names in cross references
The text naming the target manual did not match the manual the cross
reference points to.

AI-Generated: Uses Claude Opus 5
(From yocto-docs rev: c828809855fb4eec84d284c1849f9e44753c312a)

Signed-off-by: Daiane Angolini <daiane.angolini@oss.qualcomm.com>
Link: https://patch.msgid.link/20260814220720.1115397-2-daiane.angolini@oss.qualcomm.com
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit a002724c80e958ad6336db9994ad28671da79f36)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:26:37 +01:00
Daiane Angolini
2145f1ba3e ref-manual/features.rst: fix some cross references
The text does not match the cross reference, so change that.

Also, drop an extra colon.

(From yocto-docs rev: 104b8fefb09530a5fec35c14164b7637bc00c192)

Signed-off-by: Daiane Angolini <daiane.angolini@oss.qualcomm.com>
Link: https://patch.msgid.link/20260814202800.1106393-1-daiane.angolini@oss.qualcomm.com
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit cb7de72f45032e476a772a1ae8f4bd5bd20c882d)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:26:37 +01:00
Antonin Godard
7856e112fe index.rst: move release notes in their own section
The release notes are currently hidden in the welcome page, under the
"Release Manuals" section, but these changelogs/migration guides are not
release manuals per say. Move them out of the "Release Manuals" section
under their own "Release Information" section, and make them appear as a
"Release Notes and Migration Guides" section in the welcome page.

(From yocto-docs rev: 67a69f9133434129e404990d2b8a5405343580a0)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit f68f97ee4ee9b444a853569cdbe3c307d2521677)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:26:37 +01:00
Antonin Godard
751f10349c bitbake.rst: rename section to "BitBake User Manual"
This is how the documentation manual is called in the external BitBake
documentation so call it that way. Moreover this aligns better with the
other subsections of the "Manuals" section.

(From yocto-docs rev: a9f1e03127db221ef942875e6e35c1fe5da51e0e)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 77d257b88861ed690e19e5d03b6f353dfaeb9a82)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:26:36 +01:00
Antonin Godard
569c16668e contributor-guide/identify-component.rst: use the same tense as other section
All the other subsections of the Contributor Guide use a participle in
their titles, let's do the same here.

(From yocto-docs rev: ef21685393cc506ca2fec7a5f585b99b3c417e20)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit cc1179dd71a1baa03ecce5a3ebc1f3a49c1c7b38)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:26:36 +01:00
Antonin Godard
95f043e03b overview-manual: move the intro content in the index
The index document can act as an intro document. Having an extra intro
document to this section felt a bit superfluous, now that it is part of
the whole "Introduction and Overview" section.

(From yocto-docs rev: 5f11d2ff260cd1bfadf2070780ce81eac8b1c2fb)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 9deb3a9496e3cf36b0528d7616004c0f9cd6c427)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-08-24 14:26:36 +01:00