Hitendra Prajapati
ca2b19114c
vim: Security fix for CVE-2026-28420 & CVE-2026-46483
...
Pick patch from [1] & [2] also mentioned at NVD report in 3 & 4
[1] bb6de2105b
[2] 3fb5e58fbc
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-28420
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-46483
(From OE-Core rev: ef42f90ce86f9139e6618b351aaa58129813f544)
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:32 +01:00
Hitendra Prajapati
bac60a09b6
vim: Fix for CVE-2026-28417, CVE-2026-32249, CVE-2026-45130
...
Pick patch from [1], [2] & [3] also mentioned at NVD report in [4,5 & 6]
[1] 79348dbbc0
[2] 36d6e87542
[3] 9299332917
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-28417
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-32249
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-45130
(From OE-Core rev: e61095581f25a79964ee426899ee72236118f570)
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:32 +01:00
Hitendra Prajapati
ba66043d77
vim: fix for CVE-2026-28421, CVE-2026-41411 & CVE-2026-44656
...
Pick patch from [1], [2] & [3] also mentioned at NVD report in [4,5 & 6]
[1] 65c1a143c3
[2] c78194e41d
[3] 190cb3c2b9
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-28421
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-41411
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-44656
More info :
CVE-2026-28421 - Validate block tree indices and readfile() line bounds.
CVE-2026-41411 - Disallow backticks before attempting to expand filenames.
CVE-2026-44656 - Prevent shell execution from 'path' backticks via modelines.
(From OE-Core rev: 3fe9e5132aab67f1ee3139c88a89d5c6c94313c1)
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:32 +01:00
Hitendra Prajapati
623f85f957
vim: fix for CVE-2026-34982, CVE-2026-34714 & CVE-2026-35177
...
Pick patch from [1], [2] & [3] also mentioned at NVD report in [4,5 & 6]
[1] 75661a66a1
[2] 664701eb75
[3] 7088926316
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-34982
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-34714
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-35177
More info :
CVE-2026-34982 - vim: arbitrary command execution via modeline sandbox bypass.
CVE-2026-34714 - vim: Arbitrary code execution via crafted file.
CVE-2026-35177 - vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass.
(From OE-Core rev: 1b4ee99b86262ade31b69a2ba9f80791b15ea130)
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:32 +01:00
Theo Gaige (Schneider Electric)
d29b27fb31
dhcpcd: patch CVE-2026-56117
...
Backport patch [1] mentionned in [2]
[1] 78ea09ed16
[2] https://security-tracker.debian.org/tracker/CVE-2026-56117
(From OE-Core rev: 5c94b031f12c8623dc6eb9e05b87a004826345c1)
Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:32 +01:00
Theo Gaige (Schneider Electric)
4e6df49262
dhcpcd: patch CVE-2026-56114
...
Backport patch [1] mentionned in [2]
[1] 2f00c7bfc4
[2] https://security-tracker.debian.org/tracker/CVE-2026-56114
(From OE-Core rev: daaaedd30aac04f3440e11682b0a9ecbb2b75b1f)
Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:32 +01:00
Theo Gaige (Schneider Electric)
c223541984
dhcpcd: patch CVE-2026-56113
...
Backport patch [1] mentionned in [2]
[1] 5733d3c59a
[2] https://security-tracker.debian.org/tracker/CVE-2026-56113
(From OE-Core rev: fbfee67ed5d0c799bc1011f8463741c3b0910885)
Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:31 +01:00
Jaipaul Cheernam
37b718ecb9
curl: fix CVE-2026-5773 - wrong reuse of SMB connection
...
libcurl's SMB handler marks connections for reuse (connkeep) without
verifying that subsequent requests target the same share. This allows
a second SMB request to the same host to reuse a connection
authenticated for a different share, potentially accessing data
without proper authorization.
The upstream fix removes connection reuse for SMB entirely in
lib/protocol.c, a file introduced in curl 8.20.0. For 8.7.1, the
equivalent fix is changing connkeep() to connclose() in lib/smb.c,
which prevents the connection from being returned to the pool.
Tested with SMBv1 server (Docker dperson/samba):
Without patch: "Re-using existing connection" for different shares
With patch: New connection per request, no reuse
Binary verified: Curl_conncontrol arg changes from 0 (KEEP) to 1 (CLOSE)
Reference: https://curl.se/docs/CVE-2026-5773.html
(From OE-Core rev: 7736f905e78162ac657d7a1c790dfa5701dd6b19)
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:31 +01:00
Nate Kent
b8085938de
sudo: fix pam-wheel sed for sudo 1.9.17p2 sudoers
...
[YOCTO #16321 ]
In version 1.9.17p2, the line that the recipe uses to add the 'wheel'
group to the sudoers file does not exist. This updates the sed usage to
the actual line in question.
(From OE-Core rev: 55f7bf8cd9516971d6d01c1c890bc4c1df62b008)
Signed-off-by: Nate Kent <nathan@otiv.ai >
Tested-by: Siva Balasubramanian <sivakumar.bs@gmail.com >
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com >
Signed-off-by: Ross Burton <ross.burton@arm.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
(cherry picked from commit 76231f202a437be221c2580d4fa0fc100c453e92)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:31 +01:00
Himanshu Jadon
75cbb0daa1
tar: Fix CVE-2026-5704
...
Backport the upstream 3-commit fix chain for CVE-2026-5704.
The final CVE fix is [1], which depends on the earlier cleanup in [2]
and the behavioral change in [3]. Keep this patch order so the final
fix applies cleanly and preserves the upstream logic.
Also include upstream follow-up [4] to fix the --no-overwrite-dir ptest
regression caused by the CVE backport. Without this follow-up, tar can
temporarily chmod an existing directory even when --no-overwrite-dir is
used, which breaks the upstream --no-overwrite-dir ptest.
[1] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=b8d8a61b25588caca4efaf9bdd2e3f1a49da77e3
[2] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=112ead79312ea308e58414b74623f101b8c06f0b
[3] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=b009124ffde415515081db844d7a104e1d1c6c58
[4] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=4e742fc8674064a9fa00d4483d06aca48d5b0463
[5] https://security-tracker.debian.org/tracker/CVE-2026-5704
(From OE-Core rev: 86360db7d1ea4e5d2bac9889cf8fefe6148a90b4)
Signed-off-by: Himanshu Jadon <hjadon@cisco.com >
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
(cherry picked from commit 872d86b99ad3e77a105b386331a41f7fa40c2b72)
Signed-off-by: Himanshu Jadon <hjadon@cisco.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:31 +01:00
Daniel Turull
c70d4a799a
libssh2: fix CVE-2026-55199
...
Backport patch to fix CVE-2026-55199.
https://nvd.nist.gov/vuln/detail/CVE-2026-55199
Upstream fix:
17626857d2
Tested with ptest:
Before: PASSED: 3, FAILED: 0, SKIPPED: 0
After: PASSED: 3, FAILED: 0, SKIPPED: 0
Reviewed-by: Anders Heimer <anders.heimer@est.tech >
(From OE-Core rev: 2da74d75a8719db63979f132b456afdbd80395ef)
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com >
(cherry picked from commit 5b52af4a02849c1ce74491056a2d13e4e3b6ad2d)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:31 +01:00
Daniel Turull
af5ab14071
libssh2: fix CVE-2026-55200
...
Backport patch to fix CVE-2026-55200.
https://nvd.nist.gov/vuln/detail/CVE-2026-55200
Upstream fix:
97acf3dfda
Tested with ptest:
Before: PASSED: 3, FAILED: 0, SKIPPED: 0
After: PASSED: 3, FAILED: 0, SKIPPED: 0
Reviewed-by: Anders Heimer <anders.heimer@est.tech >
(From OE-Core rev: a610461f9040644bec9f1b9be23dcfff121df888)
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com >
(cherry picked from commit 42c8c6ec3066dc47b9eeeba0247ffa927193abff)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-20 09:04:31 +01:00
Antonin Godard
e146cbbc73
docs-wide: fix various broken links
...
Fix various broken links found using the linkcheck builder, in various
places of the documentation. For most, the replacing link is the
equivalent new link.
(From yocto-docs rev: 5f708a1bc31ae94dd3513615b0ce079aa7897628)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit 358519ca6406a89fee42c45dcaf63a37a374f33c)
[AG: fix conflict in variables.rst, due to changes to new variables in master]
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-15 18:39:01 +01:00
Antonin Godard
cbaaf0dcf7
migration-guides/release-notes-5.0.rst: remove broken link
...
https://no-color.org seems down, so remove the link.
(From yocto-docs rev: 615ae29b1d00e56b76bc86982848a152392ee691)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit 45f54eca0f7ba4a56ce7dd8a1a388eef1eeffc45)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-15 18:39:01 +01:00
Antonin Godard
84db80f823
ref-manual/images.rst: update obsolete VMWare links
...
VMWare Player has been discontinued in 2024 so remove the link. What
seems to be remaining is VMWare Fusions and Workstation so provide that
link only.
(From yocto-docs rev: f139c98f658e83328169cb90d119855e43a5bc83)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit 7c969dcbebf5cccb28ccbf2370dc8b52cbd08974)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-15 18:39:01 +01:00
Antonin Godard
6dc01c1e09
ref-manual/classes.rst: replace obsolete mailing list thread
...
I found this one by looking at the archive of the link on
https://web.archive.org and then locating the thread on
lists.yoctoproject.org by its title.
(From yocto-docs rev: a39ce713ec34964776cb7562c6bd7dad9e4b675d)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit 5e792ff01d463a7eca21b7be50124d7c10ff8559)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-15 18:39:01 +01:00
Antonin Godard
be96cd2ddb
docs-wide: fix broken path links
...
Fix link that forget to add a leading '/', by looking at the output of
'grep -E -r --no-filename -o 'href="http.://[^/"]+' | sort | uniq' in
the HTML output.
(From yocto-docs rev: 5e1aade33c75ce58bfb20f0118a0c862b03f7b7b)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit 12a5d2add529e789480fa782af3803dada982869)
[AG: fix conflicts: only applies to
migration-guides/release-notes-3.4.2.rst]
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-15 18:39:01 +01:00
Antonin Godard
fbbf0d711c
migration-guides/release-notes-3.4.2.rst: fix a broken link
...
Remove the extra '`'.
(From yocto-docs rev: 95ca2f097165b7689498575db282937a0fb0212a)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit 4fd8cc10d3749f6ab3a372f943b5586f465565fb)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-15 18:39:01 +01:00
Robert P. J. Day
be05e58dcf
ref-manual: add "KERNEL_IMAGE_STRIP_EXTRA_SECTIONS" to variables
...
Add this variable to the variables glossary, and add links to it and
back to the do_strip() task for completeness.
(From yocto-docs rev: cc4b7ffb3b2558ae796decbd216302e253addf02)
Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca >
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit f43fc622d2fd6bc832a2993841b2020f86c6475c)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-15 18:39:01 +01:00
Robert P. J. Day
9ba4cbc08e
ref-manual: expand on kernel "do_sizecheck" task
...
Expand on the description of do_sizecheck() to mention that it will
size-check on *all* kernel images listed in KERNEL_IMAGETYPES.
(From yocto-docs rev: 0a7d6b399d6354985527ed5fa7c2a0b132e0b640)
Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca >
[AG: kilobytes -> kibibytes
See https://lore.kernel.org/r/DJUQAEXAC03Q.2T7IDXHKVIX95@bootlin.com ]
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit b01fb11a4909fe2d3afa6cb01bd7b179429e382c)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-15 18:39:01 +01:00
Antonin Godard
84ecefc9f2
ref-manual/variables.rst: document the LOCALE_UTF8_IS_DEFAULT variable
...
Added by commit fcde0c43f7b5 ("libc-package.bbclass: add
LOCALE_UTF8_IS_DEFAULT") in OE-Core.
(From yocto-docs rev: dcf4ecb7f0dfab1b33d4ce557d04f53dff94a8ed)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit 0d5a45cb46f89bd09ed9ac59e09cff77f2868b2d)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-15 18:39:01 +01:00
Antonin Godard
6b7474f7ca
ref-manual/variables.rst: document the IMAGE_*_DEBUGFS variables
...
Added by commit 41316293e442 ("lib/oe/image.py: Add image generation
for companion debug filesystem") in OE-Core.
(From yocto-docs rev: 51c53ef1e8b4ec4afbb84252e59dd5501f405064)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit 75a69c94f5ba556fbe182c96a9bab2c561a0358e)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-03 11:19:21 +01:00
Antonin Godard
2f9c3b01d1
ref-manual/variables.rst: document the LOCALE_PATHS variable
...
Added by commit 0ffc7cf01225 ("lib/oe/package: add LOCALE_PATHS to
add define all locations for locales") in OE-Core.
(From yocto-docs rev: f8c795f6e9b94d0a747b6ccbd3fcc55c84b16919)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit b2267d27de5ac5ac163be4c740d725a181f3f2cf)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-03 11:19:21 +01:00
Antonin Godard
4d3cdfe6ce
ref-manual/variables.rst: document missing CONFLICT_*_FEATURES variables
...
Those are part of the features_check class.
(From yocto-docs rev: 297003a537798e6a4beafdd4ad520ed1c47c355a)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit fb38ef19e67b31f855bddb61ad990020d5cef234)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-03 11:19:21 +01:00
Antonin Godard
26efce957c
ref-manual/variables.rst: document the CCACHE_NATIVE_RECIPES_ALLOWED variable
...
Added by commit 87cb2be71e0c ("ccache.bbclass: Add allowed list for
native recipes") in OE-Core.
(From yocto-docs rev: 67abd242b2fa08d3ebc3f1147058d683a4e1ef85)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit 8881547719215a86a4a2e51ae3362462419a335b)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-03 11:19:21 +01:00
Robert P. J. Day
3899ca2590
ref-manual: remove all traces of "kernel_menuconfig" task
...
It's not clear why the non-existent "kernel_menuconfig" task was
documented in the reference manual, but it does not appear to have
ever existed so delete all references to it and replace with pointers
to rewritten "menuconfig" task.
(From yocto-docs rev: 5bd2aab3ad66bcc9f0b58e1b0643d71697a63da7)
Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca >
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit fdeabae4ba20e34c428ceb133ad41c4f3fedcf24)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-03 11:19:21 +01:00
Paul Barker
a448bff87a
recipe-style-guide: Clarify when License-Update tag is needed
...
As discussed in a patch review call, we don't need License-Update tags
in commits where the upstream license has not changed, and we are
instead changing the LICENSE variable to fix incorrect data.
(From yocto-docs rev: d4e19136ffee4fabfdfc5048835da64f0cfbb3eb)
Signed-off-by: Paul Barker <paul@pbarker.dev >
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
(cherry picked from commit db04faf56afded6c5f846cc60a9062e0a1ffa741)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-03 11:19:21 +01:00
Paul Barker
bb98354685
build-appliance-image: Update to scarthgap head revisions
...
(From OE-Core rev: 2814f0962f56c8d1afa4de76d2895ba9b5cb767d)
Signed-off-by: Paul Barker <paul@pbarker.dev >
yocto-5.0.19
2026-07-02 13:52:11 +01:00
Paul Barker
ba193efe20
poky.conf: Bump version for 5.0.19 release
...
(From meta-yocto rev: 2f749ae477c3b94dce71038f025180d7f612dab0)
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:26 +01:00
Richard Purdie
98335a279f
recipetool: Recognise https://git . as git urls
...
If a url has git. in it, assume it is likely to be a git cloneable url
and should be treated as such.
This allows us to switch from https://git.yoctoproject.org/git/XXX urls to
the preferred https://git.yoctoproject.org/XXX form.
(From OE-Core rev: be8b46f3a31b679b5ab532dd6e16888f868ce076)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
(cherry picked from commit cedc9209e3bae0da8d61423b16c74c49a132aa63)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:26 +01:00
Richard Purdie
4db556863d
oeqa: Drop /git/ from our urls
...
Using /git/ in our urls is rather old school and not the preferred format now.
Update the urls to the preferred form even if the other ones still work.
(From OE-Core rev: 50f40609b27c169e9da1f076172daabbf55732d0)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
(cherry picked from commit 8ac7c0c3493a6141476093bb2c1c79004c55857d)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:26 +01:00
Amaury Couderc
f47c0cb3bf
python3: fix CVE-2026-4224
...
Backport patch to fix CVE-2026-4224.
https://nvd.nist.gov/vuln/detail/CVE-2026-4224
Upstream fix:
642865ddf4
Tested with ptest:
Before: PASSED: 40007, FAILED: 0, SKIPPED: 1877
After: PASSED: 40006, FAILED: 0, SKIPPED: 1877
(From OE-Core rev: 736dd8c8f90d43e4bcdb0954a99764a62fccc20e)
Signed-off-by: Amaury Couderc <amaury.couderc@est.tech >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:26 +01:00
Sudhir Dumbhare
2c373fb9b9
nfs-utils: fix CVE-2025-12801
...
- This patch applies the upstream fix [5] as referenced in [7].
- To successfully apply the fixed commit, apply the dependent commits [2] to [4]
which are included in v2.8.6, as referenced in [7].
- Additionally, include dependent commit [1] from v2.8.3, as referenced in [8]
under the [2.5.4-38.2] description, along with compilation fix commit [6]
from v2.7.1
- Reference:
[1] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=cd90f2925790
[2] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=7e8b36522f58
[3] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=42f01e6a78fe
[4] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=51738ae56d92
[5] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=f36bd900a899
[6] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=a2c95e4f557a
[7] https://security-tracker.debian.org/tracker/CVE-2025-12801
[8] https://linux.oracle.com/errata/ELSA-2026-3940.html
(From OE-Core rev: a866d0438d30b1625450f68fea19e9315a4e4b36)
Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:26 +01:00
Anil Dongare
d144337355
libusb1: fix CVE-2026-23679 and CVE-2026-47104
...
- Pick the upstream patch [1] as mentioned in [2] and [3].
- To successfully apply the fixed commit, apply the dependent commits [4], which are
included in v1.0.28.
[1] bc0886173e
[2] https://security-tracker.debian.org/tracker/CVE-2026-23679 .
[3] https://security-tracker.debian.org/tracker/CVE-2026-47104 .
[4] 016a0de33a
(From OE-Core rev: c4d5735228e83c3a9afce48a39707b2ff5460fde)
Signed-off-by: Anil Dongare <adongare@cisco.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:26 +01:00
Vijay Anusuri
9504d658b8
xwayland: Fix CVE-2026-34003
...
Pick patch according to [2]
[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34003
(From OE-Core rev: 798e81f20e73b07255bdd6e669c146da905f6c00)
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:26 +01:00
Vijay Anusuri
e28bf42780
xwayland: Fix CVE-2026-34002
...
Pick patch according to [2]
[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34002
(From OE-Core rev: 0df72cf8effda9d82088062aa57159df2b197945)
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:26 +01:00
Vijay Anusuri
f54d73ee0d
xwayland: Fix CVE-2026-34001
...
Pick patch according to [2]
[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34001
(From OE-Core rev: 1411caa0781811b7ee452edb04ffdcf3acc92a91)
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:25 +01:00
Vijay Anusuri
de68828aa2
xwayland: Fix CVE-2026-34000
...
Pick patch according to [2]
[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34000
(From OE-Core rev: af54fbd683bf8a143b2327a74babe372e1b6f909)
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:25 +01:00
Vijay Anusuri
b96bba2f35
xwayland: Fix CVE-2026-33999
...
Pick patch according to [2]
[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-33999
(From OE-Core rev: 7060d5970c1c80631ac0c5857fe6b76176f535c9)
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:25 +01:00
Theo Gaige (Schneider Electric)
e2d512c2e7
go: patch CVE-2026-27145
...
Backport patch from [1]
[1] https://go.dev/cl/783621
(From OE-Core rev: 209a1b3a48b8e3996e1b53f2d7efe335855b7375)
Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:25 +01:00
Hitendra Prajapati
61f170a32d
libsoup: fix for CVE-2026-2369
...
Pick patch from [1] also mentioned at Debian report in [2]
[1] af4bde9902
[2] https://security-tracker.debian.org/tracker/CVE-2026-2369
Note: Issue introduced by the fix for CVE-2025-32052.
(From OE-Core rev: 6ca4635dfe2c7fb277af3409931c66f7863af890)
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:25 +01:00
Hitendra Prajapati
8820ef32b5
libsoup: fix for CVE-2025-11021
...
Pick patch from [1] also mentioned at Debian report in [2]
[1] 9e1a427d2f
[2] https://security-tracker.debian.org/tracker/CVE-2025-11021
(From OE-Core rev: f360fdedfb500cecf6d4e860d599c57b11d6e31d)
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com >
[YC: The CVE fixing patch is d010b0bbd in 3.6.6 (current master/wrynose)]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:25 +01:00
Yoann Congal
e9dcaec506
gawk-native: fix gcc-15/C23 compilation issues
...
On Ubuntu 26.04, GCC 15 defaults to std=c23 and that results in build
failure:
| ../gawk-5.3.0/io.c: In function ‘iop_alloc’:
| ../gawk-5.3.0/io.c:3389:31: error: assignment to ‘ssize_t (*)(int, void *, size_t)’ {aka ‘long int (*)(int, void *, long unsigned int)’} from incompatible pointer type ‘ssize_t (*)(void)’ {aka ‘long int (*)(void)’} [-Wincompatible-pointer-types]
| 3389 | iop->public.read_func = ( ssize_t(*)() ) read;
| | ^
Fix this by (partially) backporting an upstream patch.
(From OE-Core rev: 790bccfd8b82809e87311b24f71cf9f8e6a02b5e)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:25 +01:00
Ross Burton
2bf810addd
gawk: trim native build configuration
...
When we build gawk-native it is only for use in builds where the host
gawk output isn't reproducible across versions[1]. As such it doesn't
need support for readline or mprf, and by removing those from gawk-native
we can get building gawk-native sooner.
[1] oe-core c5bbf0a60b ("gawk: use native gawk when building glibc and grub")
(From OE-Core rev: c80a422c9c1392127a431c2dd38b203266b0b1ed)
Signed-off-by: Ross Burton <ross.burton@arm.com >
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com >
Signed-off-by: Ross Burton <ross.burton@arm.com >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
(cherry picked from commit 1e6b810f60fd45856fc6a57270bf85342bcd9415)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:25 +01:00
Richard Purdie
09e4ebfa59
grub/glibc: Bump versions to resolve hashequiv/reproducibility issues
...
After the gawk dependency change, we need to change PR/hashequiv version
to replace the corrupted sstate/hashequiv data.
(From OE-Core rev: a455b21f9170b3f2d74763b5bf99625dbda81ff9)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
(cherry picked from commit f0f7632595792a73ea0a935b924e8bdf9954ec7b)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:25 +01:00
Alexander Kanavin
1c5f26e47e
gawk: use native gawk when building glibc and grub
...
Different versions of gawk can produce different output,
so depending on which version is installed on the build host,
reproducibility issues can occur:
https://bugzilla.yoctoproject.org/show_bug.cgi?id=16072
So far only glibc and grub have been identified to have
the issue; probably more fixes of similar nature will be
required going forward.
Adjust the gawk recipe to apply target-only tweaks
(particularly the removal of awk symlink to allow for alternatives)
to only target and nativesdk variants, so that native installs
both awk and gawk executables.
[YOCTO #16072 ]
(From OE-Core rev: 288ecfd7d9cd24222cc0f1277105c15cf0889718)
Signed-off-by: Alexander Kanavin <alex@linutronix.de >
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org >
(cherry picked from commit c5bbf0a60b1d63e68f849a63e5d3872954e7cd3f)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-07-02 13:42:25 +01:00
Bruce Ashfield
3482e7f32a
linux-yocto/6.6: address ltp hang
...
Integrating the following commit(s) to linux-yocto/6.6:
1/1 [
Author: Baokun Li
Email: libaokun1@huawei.com
Subject: ext4: get rid of ppath in get_ext_path()
Date: Thu, 22 Aug 2024 10:35:32 +0800
The use of path and ppath is now very confusing, so to make the code more
readable, pass path between functions uniformly, and get rid of ppath.
After getting rid of ppath in get_ext_path(), its caller may pass an error
pointer to ext4_free_ext_path(), so it needs to teach ext4_free_ext_path()
and ext4_ext_drop_refs() to skip the error pointer. No functional changes.
Signed-off-by: Baokun Li <libaokun1@huawei.com >
Reviewed-by: Jan Kara <jack@suse.cz >
Reviewed-by: Ojaswin Mujoo <ojaswin@linux.ibm.com >
Tested-by: Ojaswin Mujoo <ojaswin@linux.ibm.com >
Link: https://patch.msgid.link/20240822023545.1994557-13-libaokun@huaweicloud.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu >
]
(From OE-Core rev: 737293bead3e7b994347e47f09bc69437479d50c)
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com >
[YC: more detail at https://lore.kernel.org/openembedded-core/DJGKEQF8GRU1.RF7JY64COTAA@smile.fr/T/#u ]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-06-26 16:55:55 +01:00
Bruce Ashfield
8cfb09a6b0
linux-yocto/6.6: genericarm64 fix configuration audit warning
...
Integrating the following commit(s) to linux-yocto/.:
1/1 [
Author: Bruce Ashfield
Email: bruce.ashfield@gmail.com
Subject: genericarm64/serial: change SERIAL_IMX_CONSOLE to =y
Date: Fri, 19 Jun 2026 00:54:55 +0200
With the following upstream commit, this option is no longer
tristate, so we set it to =y instead:
commit 3f8b835a63341163da0400befb3c6e8f6d4085da
Author: Randy Dunlap <rdunlap@infradead.org >
Date: Sat Jan 10 15:26:40 2026 -0800
serial: imx: change SERIAL_IMX_CONSOLE to bool
[ Upstream commit 79527d86ba91c2d9354832d19fd12b3baa66bd10 ]
SERIAL_IMX_CONSOLE is a build option for the imx driver (SERIAL_IMX).
It does not build a separate console driver file, so it can't be built
as a module since it isn't built at all.
Change the Kconfig symbol from tristate to bool and update the help
text accordingly.
Fixes: 0db4f9b91c86 ("tty: serial: imx: enable imx serial console port as module")
Signed-off-by: Randy Dunlap <rdunlap@infradead.org >
Link: https://patch.msgid.link/20260110232643.3533351-2-rdunlap@infradead.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org >
Signed-off-by: Sasha Levin <sashal@kernel.org >
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com >
(cherry picked from commit 465cb5bcefd72f429e0b3ad6ab5b3fcff5b390fc)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com >
]
(From OE-Core rev: 535c5940d92c39d220ab2d36b15c2dc31b41b8e0)
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-06-26 16:55:55 +01:00
He Zhe
e5db0f30c8
lttng-modules: Fix trace_hrtimer_start build failure
...
Fix the following build failure
probes/../../include/lttng/tracepoint-event-impl.h:133:6: error: conflicting
types for 'trace_hrtimer_start'; have 'void(struct hrtimer *, enum hrtimer_mode)'
133 | void trace_##_name(_proto);
| ^~~~~~
(From OE-Core rev: e0598e2bbf9513ad71dea185a540de16996c4114)
Signed-off-by: He Zhe <zhe.he@windriver.com >
[YC: backported from wrynose commit e32cbc177dae ("lttng-modules: Fix
trace_hrtimer_start build failure").
This is a partial backport of commit 7dae5f40e394 ("lttng-modules:
fix build against kernel 7.1+")]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-06-26 16:55:55 +01:00
Bruce Ashfield
b61b34f6f8
linux-yocto/6.6: update to v6.6.142
...
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:
924b4a879cbb Linux 6.6.142
cefa4265b111 security/keys: fix missed RCU read section on lookup
105c6a594b3f LoongArch: kprobes: Fix handling of fatal unrecoverable recursions
1f9c82855641 net: gro: don't merge zcopy skbs
f504118252af pds_core: ensure null-termination for firmware version strings
d3f3d6fa0cad pds_core: add an error code check in pdsc_dl_info_get
01f7f893d5e1 net: mana: validate rx_req_idx to prevent out-of-bounds array access
3dee2fe0c818 ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove()
d798b25c24f4 gpio: cdev: check if uAPI v2 config attributes are correctly zeroed
0f1fd5e83f0b gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n)
cd87492b79d1 string: add mem_is_zero() helper to check if memory area is all zeros
c9ea01768903 bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
40fc66218ad1 net: ag71xx: check error for platform_get_irq
2a1905730e0c Bluetooth: btmtk: fix urb->setup_packet leak in error paths
f04578422154 Bluetooth: btmtk: move btusb_mtk_hci_wmt_sync to btmtk.c
73377cf3056a Bluetooth: btmtk: rename btmediatek_data
aa58d8366269 Bluetooth: btusb: mediatek: refactor the function btusb_mtk_reset
b748250d778e Bluetooth: btmtk: add the function to get the fw name
e91687643c44 tracing: Avoid NULL return from hist_field_name() on truncation
8ba1c4ddbb1c ALSA: seq: Serialize UMP output teardown with event_input
e5604a480487 ALSA: seq: ump: Use guard() for locking
b6d3d3816c67 ptrace: Convert ptrace_attach() to use lock guards
60ef1675b652 pds_core: fix debugfs_lookup dentry leak and error handling
3231aff8ab26 pds_core: fix error handling in pdsc_devcmd_wait
1900ca8acb92 bridge: mcast: Fix a possible use-after-free when removing a bridge port
6e79715b7b8a net: bridge: Flush multicast groups when snooping is disabled
00904a73272b RDMA/rtrs: Fix use-after-free in path file creation cleanup
a7685f4d90c1 platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL
527a7990e663 platform/x86: intel-hid: Check ACPI_HANDLE() against NULL
6ea1690b24e9 platform/x86: hp_accel: Check ACPI_COMPANION() against NULL
32ba2ce2b15f platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL
566f42fb67a7 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
314a94c47d28 net: dsa: mt7530: preserve VLAN tags on trapped link-local frames
1bddf306212a net: dsa: mt7530: rename mt753x_bpdu_port_fw enum to mt753x_to_cpu_fw
d2be607d042d net: dsa: mt7530: fix FDB entries not aging out with short timeout
69a0885079c9 wifi: ath11k: fix peer resolution on rx path when peer_id=0
070e40acc59e drm/msm/snapshot: fix dumping of the unaligned regions
dd844b31f4ea spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache()
5c54c482934b net/mlx5: Do not restore destination-less TC rules
d65b279a1898 tls: Preserve sk_err across recvmsg() when data has been copied
1822997aa8c2 x86/xen: Fix xen_e820_swap_entry_with_ram()
06cc5ad2c112 net: phy: DP83TC811: add reading of abilities
d04494596b5e net: phy: c45: add genphy_c45_pma_read_ext_abilities() function
acdc12b71c9a net: tls: prevent chain-after-chain in plain text SG
131ef12057d9 net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
d38ba387244e net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
a09d07ac45e2 powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()
7256e54583ae drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
567b5e976e2e drm/msm/dsi: don't dump registers past the mapped region
b40e10c72df5 ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics
720c76b930c5 net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
9baafc2fea09 accel/qaic: Add overflow check to remap_pfn_range during mmap
f775be13d342 HID: quirks: really enable the intended work around for appledisplay
a5db6a7c062f wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm()
3d675896ea03 wifi: ath11k: fix error path leaks in some WMI WOW calls
b77be98447c4 net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference
78cf08b3be47 net: ethernet: cortina: Carry over frag counter
68c9c3ac9ce5 net: ethernet: cortina: Drop half-assembled SKB
3b249988d774 net: ethernet: cortina: Make RX SKB per-port
00efe58bbdcc netfs: Fix overrun check in netfs_extract_user_iter()
0df68fd72b2a zonefs: handle integer overflow in zonefs_fname_to_fno
eef4f71b46a9 irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT
6760af11a26e irqchip/ath79-cpu: Remove unused function
6af5fd2ffda1 phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access
b0cc58e8f749 net: lan966x: avoid unregistering netdev on register failure
9e1c9b957344 ice: fix locking in ice_dcb_rebuild()
07d77d774f71 tcp: Fix imbalanced icsk_accept_queue count.
08d355936fcf test_kprobes: clear kprobes between test runs
8a5f01446021 kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist()
99948d73a8c7 netfilter: x_tables: unregister the templates first
26b2290baaf6 btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
542b49d2cf12 ALSA: hda: cs35l56: Put ACPI device after setting companion
508b1193d63b ARM: integrator: Fix early initialization
fb3ff02dd444 pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150
7d694570281a kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS
0df3f3031517 kunit: config: Enable KUNIT_DEBUGFS by default
8b0f4e3b7ad6 firmware: arm_ffa: Skip free_pages on RX buffer alloc failure
adfff93d08a2 firmware: arm_ffa: Check for NULL FF-A ID table while driver registration
58ab91af4124 HID: uclogic: Fix regression of input name assignment
a2d1c819348b hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors
20d626463e3f hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe()
cba4f1122dfb hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe()
6b5573b63e30 hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple
4d1da9a6be5a hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
60c4b9fe1a3d hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer
d94ceb16e55b hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
f85c81e93dbd hwmon: (pmbus/adm1266) reject implausible blackbox record_count
025cfc7a09c5 hwmon: (pmbus/adm1266) seed timestamp from the real-time clock
32edd2a28e11 batman-adv: tt: fix negative tt_buff_len
22d59c72f4a4 batman-adv: tt: fix negative last_changeset_len
c2c88736022c batman-adv: tp_meter: fix race condition in send error reporting
0b1bedf114ea batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
53f931e0146a batman-adv: tp_meter: avoid use of uninit sender vars
48663158222b batman-adv: bla: fix report_work leak on backbone_gw purge
b54e459cf869 batman-adv: frag: disallow unicast fragment in fragment
c1bac194733a batman-adv: fix tp_meter counter underflow during shutdown
f653b040dad1 batman-adv: fix fragment reassembly length accounting
866ac1d57040 batman-adv: dat: handle forward allocation error
6de089b545db batman-adv: clear current gateway during teardown
70bcb678561f batman-adv: mcast: fix use-after-free in orig_node RCU release
90c398e822ca drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async
fb30a3890d62 drm/amd/display: Validate GPIO pin LUT table size before iterating
266b21b57fbb drm/amd/display: Fix integer overflow in bios_get_image()
e4d3d33ab7bd drm/bridge: megachips: remove bridge when irq request fails
25473edcdaef drm/bridge: it66121: acquire reset GPIO in probe
21ab64c77a30 drm/virtio: use uninterruptible resv lock for plane updates
371f53925a67 device property: set fwnode->secondary to NULL in fwnode_init()
fb3539b367f5 LoongArch: Remove unused code to avoid build warning
14553be882d9 RDMA/siw: Reject MPA FPDU length underflow before signed receive math
f2dc841d7dc9 spi: ti-qspi: fix use-after-free after DMA setup failure
450c319dd04d spi: sprd: fix error pointer deref after DMA setup failure
309c6058622d scsi: isci: Fix use-after-free in device removal path
9d5ae6b8d9ec phy: tegra: xusb: Fix per-pad high-speed termination calibration
45760b72e84c spi: qup: fix error pointer deref after DMA setup failure
3c83a6912c24 drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe
dab9f93251b2 KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits
e0790046f6be arm64: probes: Handle probes on hinted conditional branch instructions
f383cff9fb38 tracing: Do not call map->ops->elt_free() if elt_alloc() fails
bdc349a87f1f cifs: Fix busy dentry used after unmounting
1ced0f5a851f wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
a3a4366731a5 ice: fix setting promisc mode while adding VID filter
add70e2682c0 ixgbevf: fix use-after-free in VEPA multicast source pruning
3c5411fa4944 ipv4: raw: reject IP_HDRINCL packets with ihl < 5
f50c3ff97c83 wifi: ath11k: clear shared SRNG pointer state on restart
ce29d3bf79a2 vsock/virtio: reset connection on receiving queue overflow
cc27e989a5df vsock/vmci: fix UAF when peer resets connection during handshake
273a1481c556 ring-buffer: Fix reporting of missed events in iterator
3904b993cc17 qed: fix double free in qed_cxt_tables_alloc()
c161ad9157f5 netfilter: nft_inner: Fix IPv6 inner_thoff desync
c281e018af98 netfilter: ipset: stop hash:* range iteration at end
1e5e20031c5e netfilter: nf_queue: hold bridge skb->dev while queued
41ec2e242f17 netfilter: ip6t_hbh: reject oversized option lists
16bd798cb6d8 net: ifb: report ethtool stats over num_tx_queues
289499907399 net: bcmgenet: keep RBUF EEE/PM disabled
8420aa490041 phonet/pep: disable BH around forwarded sk_receive_skb()
be43e6b40431 Bluetooth: serialize accept_q access
a143ce77a529 Bluetooth: MGMT: validate Add Extended Advertising Data length
9d20d48be2c4 Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
fe69f634b076 Bluetooth: bnep: Fix UAF read of dev->name
3af41ee7ebec Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
5d86d2f1b4d9 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
6f63a60580eb net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
686b4283f82c drivers/base/memory: fix memory block reference leak in poison accounting
29cd94e678fc efi: Allocate runtime workqueue before ACPI init
7b6f8c8eb93f ALSA: asihpi: Fix potential OOB array access at reading cache
41a766c64729 ALSA: pcm: Don't setup bogus iov_iter for silencing
dade81458966 ALSA: ua101: Reject too-short USB descriptors
0dbf64c50244 hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
adcfb16ae402 smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close
7df1df6f40c0 smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
9d378e17c864 ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
e43cb36d4d78 ksmbd: fix null pointer dereference in compare_guid_key()
082351f9d400 mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()
31527d80234c sysfs: don't remove existing directory on update failure
ad7520628c74 Revert "af_unix: Reject SIOCATMARK on non-stream sockets"
f624070c322d Revert "s390/cio: Update purge function to unregister the unused subchannels"
7963b6141b4c Revert "ice: Remove jumbo_remove step from TX path"
6331b0f7b71e Revert "ice: fix double-free of tx_buf skb"
2035acfb1722 smb: client: reject userspace cifs.spnego descriptions
3106f326f67c af_unix: Give up GC if MSG_PEEK intervened.
3a436932eb39 ksmbd: close durable scavenger races against m_fp_list lookups
712cdf917e77 ksmbd: validate owner of durable handle on reconnect
7f0cb478703c ksmbd: add durable scavenger timer
50a23fa28e76 ksmbd: avoid reclaiming expired durable opens by the client
2682bf9a804b Revert "x86/vdso: Fix output operand size of RDPID"
ba5b43db126a wifi: mac80211: check tdls flag in ieee80211_tdls_oper
a052c2d8399a s390/debug: Reject zero-length input before trimming a newline
492349e5e4a3 driver core: platform: use generic driver_override infrastructure
64a3ee535bd7 driver core: generalize driver_override in struct device
fabfed1afe27 spi: spidev: fix lock inversion between spi_lock and buf_lock
6a3af482188f mptcp: pm: ADD_ADDR rtx: free sk if last
9426265e157d mptcp: pm: ADD_ADDR rtx: always decrease sk refcount
19a3ec9ef176 mptcp: pm: ADD_ADDR rtx: allow ID 0
b386aa38b81d mptcp: sync the msk->sndbuf at accept() time
(From OE-Core rev: ba0f120f6cdbcc1d2782bef27c101e20a11f0f19)
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com >
Signed-off-by: Yoann Congal <yoann.congal@smile.fr >
Signed-off-by: Paul Barker <paul@pbarker.dev >
2026-06-26 16:55:55 +01:00