Hetvi Thakar
00e6a3df8c
patch: Fix CVE-2026-56288
...
This patch applies the upstream fix referenced by NVD in [2], using
the commit shown in [1].
[1] https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=e6d6a4e021660679d7fc9150f981d4920f722313
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-56288
(From OE-Core rev: 1b1e13055b4eed838e1411d91dea46de08e1d72f)
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
(cherry picked from commit a30cd69993f9f48d5cf55e57181e49171f0a1b7a)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2026-09-04 10:39:10 +01:00
Hetvi Thakar
f03efa1107
patch: Fix CVE-2026-56289
...
This patch applies the upstream fix referenced by NVD in [2], using
the commit shown in [1].
[1] https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-56289
(From OE-Core rev: b1540647185015c99fbf421d889547a6c10e7e29)
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
(cherry picked from commit 48c1aa91e829a87c398e8c012cde45cd8c1aab0a)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2026-09-04 10:39:10 +01:00
Richard Purdie
b0130fcf91
meta/meta-selftest/meta-skeleton: Update LICENSE variable to use SPDX license identifiers
...
An automated conversion using scripts/contrib/convert-spdx-licenses.py to
convert to use the standard SPDX license identifiers. Two recipes in meta-selftest
were not converted as they're that way specifically for testing. A change in
linux-firmware was also skipped and may need a more manual tweak.
(From OE-Core rev: ceda3238cdbf1beb216ae9ddb242470d5dfc25e0)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2022-02-20 16:45:25 +00:00
Richard Purdie
bb6ddc3691
Convert to new override syntax
...
This is the result of automated script conversion:
scripts/contrib/convert-overrides.py <oe-core directory>
converting the metadata to use ":" as the override character instead of "_".
(From OE-Core rev: 42344347be29f0997cc2f7636d9603b1fe1875ae)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2021-08-02 15:44:10 +01:00
Scott Murray
897a7d5679
patch: fix CVE-2019-20633
...
* CVE detail: https://nvd.nist.gov/vuln/detail/CVE-2019-20633
* upstream tracking: https://savannah.gnu.org/bugs/index.php?56683
* Fixes potential for double free after incomplete fix for CVE-2018-6952
- src/pch.c (another_hunk): Avoid invalid memory access in context format
diffs.
(From OE-Core rev: be71dd2cc16a4c0d244a76a748f08ca0d9bfeba0)
Signed-off-by: Scott Murray <scott.murray@konsulko.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2021-01-01 23:15:13 +00:00
Richard Purdie
500206534f
patch: Extend to native/nativesdk and depend upon
...
There is a bug in patch 2.7.3 and earlier where index lines
in patches can change file modes when they shouldn't:
http://git.savannah.gnu.org/cgit/patch.git/patch/?id=82b800c9552a088a241457948219d25ce0a407a4
This leaks into debug sources in particular (e.g. tcp-wrappers where
source files are read-only). Add the dependency to target recipes
to avoid this problem until we can rely on 2.7.4 or later.
We could try and remove all index lines from patch files but it will be a
losing battle. We could try and identify all the recipes which change
modes on files in patches but again, its a losing battle.
Instead, compromise and have patch-native as a dependency
for target recipes. We use patch-replacement-native since patch-native
is in ASSUME_PROVIDED.
Also add nativesdk-patch to buildtools-tarball.
[YOCTO #13777 ]
(From OE-Core rev: 5ed0840c93804488cd1c1aba6cb382b2434714a5)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2020-02-06 12:16:34 +00:00
Anuj Mittal
f326d31c4e
patch: backport fixes
...
The original fix for CVE-2018-1000156 was incomplete. Backport more
fixes done later for a complete fix.
Also see:
https://savannah.gnu.org/bugs/index.php?53820
(From OE-Core rev: 9ea833b7d1655e042a513ea2225468c84f1c8bfb)
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com >
Signed-off-by: Ross Burton <ross.burton@intel.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2019-08-22 22:48:26 +01:00
Trevor Gamblin
6e5636d56b
patch: fix CVE-2019-13638
...
(From OE-Core rev: b59b1222b3f73f982286222a583de09c661dc781)
Signed-off-by: Trevor Gamblin <trevor.gamblin@windriver.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2019-08-13 09:37:37 +01:00
Anuj Mittal
df9d8dbe75
patch: fix CVE-2019-13636
...
(From OE-Core rev: f201b9db5d148cb9fe03b78ca085493a27f7e24c)
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2019-07-31 23:03:01 +01:00
Hongxu Jia
a11008a90d
patch: fix CVE-2018-6952
...
(From OE-Core rev: 1314a6953aa647706107557faaba8574e307d2bd)
Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2018-08-23 07:50:01 +01:00
Jackie Huang
16174d9342
patch: fix CVE-2018-1000156
...
* CVE detail: https://nvd.nist.gov/vuln/detail/CVE-2018-1000156
* upstream tracking: https://savannah.gnu.org/bugs/index.php?53566
* Fix arbitrary command execution in ed-style patches:
- src/pch.c (do_ed_script): Write ed script to a temporary file instead
of piping it to ed: this will cause ed to abort on invalid commands
instead of rejecting them and carrying on.
- tests/ed-style: New test case.
- tests/Makefile.am (TESTS): Add test case.
(From OE-Core rev: 6b6ae212837a07aaefd2b675b5b527fbce2a4270)
Signed-off-by: Jackie Huang <jackie.huang@windriver.com >
Signed-off-by: Ross Burton <ross.burton@intel.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2018-04-13 16:58:07 +01:00
Jackie Huang
31714674e4
patch: fix CVE-2018-6951
...
* CVE detail: https://nvd.nist.gov/vuln/detail/CVE-2018-6951
* upstream tracking: http://savannah.gnu.org/bugs/?53132
* Fix segfault with mangled rename patch
- src/pch.c (intuit_diff_type): Ensure that two filenames are specified
for renames and copies (fix the existing check).
(From OE-Core rev: cdf74e1c67698b2d44a7460ff7d365d6da7b7b96)
Signed-off-by: Jackie Huang <jackie.huang@windriver.com >
Signed-off-by: Ross Burton <ross.burton@intel.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2018-04-13 16:58:07 +01:00
Huang Qiyu
e5969c7ec7
patch:2.7.5 -> 2.7.6
...
Upgrade patch from 2.7.5 to 2.7.6.
(From OE-Core rev: e5dcd58e5b2ef0b8e2bbe90e9bb1cede4e76bf75)
Signed-off-by: Huang Qiyu <huangqy.fnst@cn.fujitsu.com >
Signed-off-by: Ross Burton <ross.burton@intel.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
2018-03-08 10:39:32 -08:00