Commit Graph

76276 Commits

Author SHA1 Message Date
Hitendra Prajapati
ca2b19114c vim: Security fix for CVE-2026-28420 & CVE-2026-46483
Pick patch from [1] & [2] also mentioned at NVD report in 3 & 4

[1] bb6de2105b
[2] 3fb5e58fbc
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-28420
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-46483

(From OE-Core rev: ef42f90ce86f9139e6618b351aaa58129813f544)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Hitendra Prajapati
bac60a09b6 vim: Fix for CVE-2026-28417, CVE-2026-32249, CVE-2026-45130
Pick patch from [1], [2] & [3] also mentioned at NVD report in [4,5 & 6]

[1] 79348dbbc0
[2] 36d6e87542
[3] 9299332917
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-28417
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-32249
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-45130

(From OE-Core rev: e61095581f25a79964ee426899ee72236118f570)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Hitendra Prajapati
ba66043d77 vim: fix for CVE-2026-28421, CVE-2026-41411 & CVE-2026-44656
Pick patch from [1], [2] & [3] also mentioned at NVD report in [4,5 & 6]

[1] 65c1a143c3
[2] c78194e41d
[3] 190cb3c2b9
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-28421
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-41411
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-44656

More info :
CVE-2026-28421 - Validate block tree indices and readfile() line bounds.
CVE-2026-41411 - Disallow backticks before attempting to expand filenames.
CVE-2026-44656 - Prevent shell execution from 'path' backticks via modelines.

(From OE-Core rev: 3fe9e5132aab67f1ee3139c88a89d5c6c94313c1)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Hitendra Prajapati
623f85f957 vim: fix for CVE-2026-34982, CVE-2026-34714 & CVE-2026-35177
Pick patch from [1], [2] & [3] also mentioned at NVD report in [4,5 & 6]

[1] 75661a66a1
[2] 664701eb75
[3] 7088926316
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-34982
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-34714
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-35177

More info :
CVE-2026-34982 - vim: arbitrary command execution via modeline sandbox bypass.
CVE-2026-34714 - vim: Arbitrary code execution via crafted file.
CVE-2026-35177 - vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass.

(From OE-Core rev: 1b4ee99b86262ade31b69a2ba9f80791b15ea130)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Theo Gaige (Schneider Electric)
d29b27fb31 dhcpcd: patch CVE-2026-56117
Backport patch [1] mentionned in [2]

[1] 78ea09ed16

[2] https://security-tracker.debian.org/tracker/CVE-2026-56117

(From OE-Core rev: 5c94b031f12c8623dc6eb9e05b87a004826345c1)

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Theo Gaige (Schneider Electric)
4e6df49262 dhcpcd: patch CVE-2026-56114
Backport patch [1] mentionned in [2]

[1] 2f00c7bfc4

[2] https://security-tracker.debian.org/tracker/CVE-2026-56114

(From OE-Core rev: daaaedd30aac04f3440e11682b0a9ecbb2b75b1f)

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Theo Gaige (Schneider Electric)
c223541984 dhcpcd: patch CVE-2026-56113
Backport patch [1] mentionned in [2]

[1] 5733d3c59a

[2] https://security-tracker.debian.org/tracker/CVE-2026-56113

(From OE-Core rev: fbfee67ed5d0c799bc1011f8463741c3b0910885)

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Jaipaul Cheernam
37b718ecb9 curl: fix CVE-2026-5773 - wrong reuse of SMB connection
libcurl's SMB handler marks connections for reuse (connkeep) without
verifying that subsequent requests target the same share. This allows
a second SMB request to the same host to reuse a connection
authenticated for a different share, potentially accessing data
without proper authorization.

The upstream fix removes connection reuse for SMB entirely in
lib/protocol.c, a file introduced in curl 8.20.0. For 8.7.1, the
equivalent fix is changing connkeep() to connclose() in lib/smb.c,
which prevents the connection from being returned to the pool.

Tested with SMBv1 server (Docker dperson/samba):
  Without patch: "Re-using existing connection" for different shares
  With patch: New connection per request, no reuse

Binary verified: Curl_conncontrol arg changes from 0 (KEEP) to 1 (CLOSE)

Reference: https://curl.se/docs/CVE-2026-5773.html

(From OE-Core rev: 7736f905e78162ac657d7a1c790dfa5701dd6b19)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Nate Kent
b8085938de sudo: fix pam-wheel sed for sudo 1.9.17p2 sudoers
[YOCTO #16321]

In version 1.9.17p2, the line that the recipe uses to add the 'wheel'
group to the sudoers file does not exist. This updates the sed usage to
the actual line in question.

(From OE-Core rev: 55f7bf8cd9516971d6d01c1c890bc4c1df62b008)

Signed-off-by: Nate Kent <nathan@otiv.ai>
Tested-by: Siva Balasubramanian <sivakumar.bs@gmail.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 76231f202a437be221c2580d4fa0fc100c453e92)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Himanshu Jadon
75cbb0daa1 tar: Fix CVE-2026-5704
Backport the upstream 3-commit fix chain for CVE-2026-5704.

The final CVE fix is [1], which depends on the earlier cleanup in [2]
and the behavioral change in [3]. Keep this patch order so the final
fix applies cleanly and preserves the upstream logic.

Also include upstream follow-up [4] to fix the --no-overwrite-dir ptest
regression caused by the CVE backport. Without this follow-up, tar can
temporarily chmod an existing directory even when --no-overwrite-dir is
used, which breaks the upstream --no-overwrite-dir ptest.

[1] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=b8d8a61b25588caca4efaf9bdd2e3f1a49da77e3
[2] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=112ead79312ea308e58414b74623f101b8c06f0b
[3] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=b009124ffde415515081db844d7a104e1d1c6c58
[4] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=4e742fc8674064a9fa00d4483d06aca48d5b0463
[5] https://security-tracker.debian.org/tracker/CVE-2026-5704

(From OE-Core rev: 86360db7d1ea4e5d2bac9889cf8fefe6148a90b4)

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 872d86b99ad3e77a105b386331a41f7fa40c2b72)
Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Daniel Turull
c70d4a799a libssh2: fix CVE-2026-55199
Backport patch to fix CVE-2026-55199.
https://nvd.nist.gov/vuln/detail/CVE-2026-55199

Upstream fix:
  17626857d2

Tested with ptest:
Before: PASSED: 3, FAILED: 0, SKIPPED: 0
After: PASSED: 3, FAILED: 0, SKIPPED: 0

Reviewed-by: Anders Heimer <anders.heimer@est.tech>
(From OE-Core rev: 2da74d75a8719db63979f132b456afdbd80395ef)

Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
(cherry picked from commit 5b52af4a02849c1ce74491056a2d13e4e3b6ad2d)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Daniel Turull
af5ab14071 libssh2: fix CVE-2026-55200
Backport patch to fix CVE-2026-55200.
https://nvd.nist.gov/vuln/detail/CVE-2026-55200

Upstream fix:
  97acf3dfda

Tested with ptest:
Before: PASSED: 3, FAILED: 0, SKIPPED: 0
After: PASSED: 3, FAILED: 0, SKIPPED: 0

Reviewed-by: Anders Heimer <anders.heimer@est.tech>
(From OE-Core rev: a610461f9040644bec9f1b9be23dcfff121df888)

Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
(cherry picked from commit 42c8c6ec3066dc47b9eeeba0247ffa927193abff)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Antonin Godard
e146cbbc73 docs-wide: fix various broken links
Fix various broken links found using the linkcheck builder, in various
places of the documentation. For most, the replacing link is the
equivalent new link.

(From yocto-docs rev: 5f708a1bc31ae94dd3513615b0ce079aa7897628)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 358519ca6406a89fee42c45dcaf63a37a374f33c)
[AG: fix conflict in variables.rst, due to changes to new variables in master]
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
cbaaf0dcf7 migration-guides/release-notes-5.0.rst: remove broken link
https://no-color.org seems down, so remove the link.

(From yocto-docs rev: 615ae29b1d00e56b76bc86982848a152392ee691)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 45f54eca0f7ba4a56ce7dd8a1a388eef1eeffc45)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
84db80f823 ref-manual/images.rst: update obsolete VMWare links
VMWare Player has been discontinued in 2024 so remove the link. What
seems to be remaining is VMWare Fusions and Workstation so provide that
link only.

(From yocto-docs rev: f139c98f658e83328169cb90d119855e43a5bc83)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 7c969dcbebf5cccb28ccbf2370dc8b52cbd08974)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
6dc01c1e09 ref-manual/classes.rst: replace obsolete mailing list thread
I found this one by looking at the archive of the link on
https://web.archive.org and then locating the thread on
lists.yoctoproject.org by its title.

(From yocto-docs rev: a39ce713ec34964776cb7562c6bd7dad9e4b675d)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 5e792ff01d463a7eca21b7be50124d7c10ff8559)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
be96cd2ddb docs-wide: fix broken path links
Fix link that forget to add a leading '/', by looking at the output of
'grep -E -r --no-filename -o 'href="http.://[^/"]+' | sort | uniq' in
the HTML output.

(From yocto-docs rev: 5e1aade33c75ce58bfb20f0118a0c862b03f7b7b)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 12a5d2add529e789480fa782af3803dada982869)
[AG: fix conflicts: only applies to
 migration-guides/release-notes-3.4.2.rst]
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
fbbf0d711c migration-guides/release-notes-3.4.2.rst: fix a broken link
Remove the extra '`'.

(From yocto-docs rev: 95ca2f097165b7689498575db282937a0fb0212a)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 4fd8cc10d3749f6ab3a372f943b5586f465565fb)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Robert P. J. Day
be05e58dcf ref-manual: add "KERNEL_IMAGE_STRIP_EXTRA_SECTIONS" to variables
Add this variable to the variables glossary, and add links to it and
back to the do_strip() task for completeness.

(From yocto-docs rev: cc4b7ffb3b2558ae796decbd216302e253addf02)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit f43fc622d2fd6bc832a2993841b2020f86c6475c)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Robert P. J. Day
9ba4cbc08e ref-manual: expand on kernel "do_sizecheck" task
Expand on the description of do_sizecheck() to mention that it will
size-check on *all* kernel images listed in KERNEL_IMAGETYPES.

(From yocto-docs rev: 0a7d6b399d6354985527ed5fa7c2a0b132e0b640)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
[AG: kilobytes -> kibibytes
 See https://lore.kernel.org/r/DJUQAEXAC03Q.2T7IDXHKVIX95@bootlin.com]
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit b01fb11a4909fe2d3afa6cb01bd7b179429e382c)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
84ecefc9f2 ref-manual/variables.rst: document the LOCALE_UTF8_IS_DEFAULT variable
Added by commit fcde0c43f7b5 ("libc-package.bbclass: add
LOCALE_UTF8_IS_DEFAULT") in OE-Core.

(From yocto-docs rev: dcf4ecb7f0dfab1b33d4ce557d04f53dff94a8ed)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 0d5a45cb46f89bd09ed9ac59e09cff77f2868b2d)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
6b7474f7ca ref-manual/variables.rst: document the IMAGE_*_DEBUGFS variables
Added by commit 41316293e442 ("lib/oe/image.py: Add image generation
for companion debug filesystem") in OE-Core.

(From yocto-docs rev: 51c53ef1e8b4ec4afbb84252e59dd5501f405064)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 75a69c94f5ba556fbe182c96a9bab2c561a0358e)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Antonin Godard
2f9c3b01d1 ref-manual/variables.rst: document the LOCALE_PATHS variable
Added by commit 0ffc7cf01225 ("lib/oe/package: add LOCALE_PATHS to
add define all locations for locales") in OE-Core.

(From yocto-docs rev: f8c795f6e9b94d0a747b6ccbd3fcc55c84b16919)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit b2267d27de5ac5ac163be4c740d725a181f3f2cf)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Antonin Godard
4d3cdfe6ce ref-manual/variables.rst: document missing CONFLICT_*_FEATURES variables
Those are part of the features_check class.

(From yocto-docs rev: 297003a537798e6a4beafdd4ad520ed1c47c355a)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit fb38ef19e67b31f855bddb61ad990020d5cef234)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Antonin Godard
26efce957c ref-manual/variables.rst: document the CCACHE_NATIVE_RECIPES_ALLOWED variable
Added by commit 87cb2be71e0c ("ccache.bbclass: Add allowed list for
native recipes") in OE-Core.

(From yocto-docs rev: 67abd242b2fa08d3ebc3f1147058d683a4e1ef85)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 8881547719215a86a4a2e51ae3362462419a335b)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Robert P. J. Day
3899ca2590 ref-manual: remove all traces of "kernel_menuconfig" task
It's not clear why the non-existent "kernel_menuconfig" task was
documented in the reference manual, but it does not appear to have
ever existed so delete all references to it and replace with pointers
to rewritten "menuconfig" task.

(From yocto-docs rev: 5bd2aab3ad66bcc9f0b58e1b0643d71697a63da7)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit fdeabae4ba20e34c428ceb133ad41c4f3fedcf24)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Paul Barker
a448bff87a recipe-style-guide: Clarify when License-Update tag is needed
As discussed in a patch review call, we don't need License-Update tags
in commits where the upstream license has not changed, and we are
instead changing the LICENSE variable to fix incorrect data.

(From yocto-docs rev: d4e19136ffee4fabfdfc5048835da64f0cfbb3eb)

Signed-off-by: Paul Barker <paul@pbarker.dev>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit db04faf56afded6c5f846cc60a9062e0a1ffa741)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Paul Barker
bb98354685 build-appliance-image: Update to scarthgap head revisions
(From OE-Core rev: 2814f0962f56c8d1afa4de76d2895ba9b5cb767d)

Signed-off-by: Paul Barker <paul@pbarker.dev>
yocto-5.0.19
2026-07-02 13:52:11 +01:00
Paul Barker
ba193efe20 poky.conf: Bump version for 5.0.19 release
(From meta-yocto rev: 2f749ae477c3b94dce71038f025180d7f612dab0)

Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Richard Purdie
98335a279f recipetool: Recognise https://git. as git urls
If a url has git. in it, assume it is likely to be a git cloneable url
and should be treated as such.

This allows us to switch from https://git.yoctoproject.org/git/XXX urls to
the preferred https://git.yoctoproject.org/XXX form.

(From OE-Core rev: be8b46f3a31b679b5ab532dd6e16888f868ce076)

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit cedc9209e3bae0da8d61423b16c74c49a132aa63)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Richard Purdie
4db556863d oeqa: Drop /git/ from our urls
Using /git/ in our urls is rather old school and not the preferred format now.
Update the urls to the preferred form even if the other ones still work.

(From OE-Core rev: 50f40609b27c169e9da1f076172daabbf55732d0)

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 8ac7c0c3493a6141476093bb2c1c79004c55857d)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Amaury Couderc
f47c0cb3bf python3: fix CVE-2026-4224
Backport patch to fix CVE-2026-4224.
https://nvd.nist.gov/vuln/detail/CVE-2026-4224

Upstream fix:
  642865ddf4

Tested with ptest:
Before: PASSED: 40007, FAILED: 0, SKIPPED: 1877
After: PASSED: 40006, FAILED: 0, SKIPPED: 1877

(From OE-Core rev: 736dd8c8f90d43e4bcdb0954a99764a62fccc20e)

Signed-off-by: Amaury Couderc <amaury.couderc@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Sudhir Dumbhare
2c373fb9b9 nfs-utils: fix CVE-2025-12801
- This patch applies the upstream fix [5] as referenced in [7].
- To successfully apply the fixed commit, apply the dependent commits [2] to [4]
  which are included in v2.8.6, as referenced in [7].
- Additionally, include dependent commit [1] from v2.8.3, as referenced in [8]
  under the [2.5.4-38.2] description, along with compilation fix commit [6]
  from v2.7.1
- Reference:
  [1] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=cd90f2925790
  [2] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=7e8b36522f58
  [3] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=42f01e6a78fe
  [4] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=51738ae56d92
  [5] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=f36bd900a899
  [6] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=a2c95e4f557a
  [7] https://security-tracker.debian.org/tracker/CVE-2025-12801
  [8] https://linux.oracle.com/errata/ELSA-2026-3940.html

(From OE-Core rev: a866d0438d30b1625450f68fea19e9315a4e4b36)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Anil Dongare
d144337355 libusb1: fix CVE-2026-23679 and CVE-2026-47104
- Pick the upstream patch [1] as mentioned in [2] and [3].
- To successfully apply the fixed commit, apply the dependent commits [4], which are
  included in v1.0.28.

[1] bc0886173e
[2] https://security-tracker.debian.org/tracker/CVE-2026-23679.
[3] https://security-tracker.debian.org/tracker/CVE-2026-47104.
[4] 016a0de33a

(From OE-Core rev: c4d5735228e83c3a9afce48a39707b2ff5460fde)

Signed-off-by: Anil Dongare <adongare@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Vijay Anusuri
9504d658b8 xwayland: Fix CVE-2026-34003
Pick patch according to [2]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34003

(From OE-Core rev: 798e81f20e73b07255bdd6e669c146da905f6c00)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Vijay Anusuri
e28bf42780 xwayland: Fix CVE-2026-34002
Pick patch according to [2]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34002

(From OE-Core rev: 0df72cf8effda9d82088062aa57159df2b197945)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Vijay Anusuri
f54d73ee0d xwayland: Fix CVE-2026-34001
Pick patch according to [2]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34001

(From OE-Core rev: 1411caa0781811b7ee452edb04ffdcf3acc92a91)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Vijay Anusuri
de68828aa2 xwayland: Fix CVE-2026-34000
Pick patch according to [2]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34000

(From OE-Core rev: af54fbd683bf8a143b2327a74babe372e1b6f909)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Vijay Anusuri
b96bba2f35 xwayland: Fix CVE-2026-33999
Pick patch according to [2]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-33999

(From OE-Core rev: 7060d5970c1c80631ac0c5857fe6b76176f535c9)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Theo Gaige (Schneider Electric)
e2d512c2e7 go: patch CVE-2026-27145
Backport patch from [1]

[1] https://go.dev/cl/783621

(From OE-Core rev: 209a1b3a48b8e3996e1b53f2d7efe335855b7375)

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Hitendra Prajapati
61f170a32d libsoup: fix for CVE-2026-2369
Pick patch from [1] also mentioned at Debian report in [2]

[1] af4bde9902
[2] https://security-tracker.debian.org/tracker/CVE-2026-2369

Note: Issue introduced by the fix for CVE-2025-32052.

(From OE-Core rev: 6ca4635dfe2c7fb277af3409931c66f7863af890)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Hitendra Prajapati
8820ef32b5 libsoup: fix for CVE-2025-11021
Pick patch from [1] also mentioned at Debian report in [2]

[1] 9e1a427d2f
[2] https://security-tracker.debian.org/tracker/CVE-2025-11021

(From OE-Core rev: f360fdedfb500cecf6d4e860d599c57b11d6e31d)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
[YC: The CVE fixing patch is d010b0bbd in 3.6.6 (current master/wrynose)]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Yoann Congal
e9dcaec506 gawk-native: fix gcc-15/C23 compilation issues
On Ubuntu 26.04, GCC 15 defaults to std=c23 and that results in build
failure:
| ../gawk-5.3.0/io.c: In function ‘iop_alloc’:
| ../gawk-5.3.0/io.c:3389:31: error: assignment to ‘ssize_t (*)(int,  void *, size_t)’ {aka ‘long int (*)(int,  void *, long unsigned int)’} from incompatible pointer type ‘ssize_t (*)(void)’ {aka ‘long int (*)(void)’} [-Wincompatible-pointer-types]
|  3389 |         iop->public.read_func = ( ssize_t(*)() ) read;
|       |                               ^

Fix this by (partially) backporting an upstream patch.

(From OE-Core rev: 790bccfd8b82809e87311b24f71cf9f8e6a02b5e)

Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Ross Burton
2bf810addd gawk: trim native build configuration
When we build gawk-native it is only for use in builds where the host
gawk output isn't reproducible across versions[1]. As such it doesn't
need support for readline or mprf, and by removing those from gawk-native
we can get building gawk-native sooner.

[1] oe-core c5bbf0a60b ("gawk: use native gawk when building glibc and grub")

(From OE-Core rev: c80a422c9c1392127a431c2dd38b203266b0b1ed)

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 1e6b810f60fd45856fc6a57270bf85342bcd9415)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Richard Purdie
09e4ebfa59 grub/glibc: Bump versions to resolve hashequiv/reproducibility issues
After the gawk dependency change, we need to change PR/hashequiv version
to replace the corrupted sstate/hashequiv data.

(From OE-Core rev: a455b21f9170b3f2d74763b5bf99625dbda81ff9)

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit f0f7632595792a73ea0a935b924e8bdf9954ec7b)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Alexander Kanavin
1c5f26e47e gawk: use native gawk when building glibc and grub
Different versions of gawk can produce different output,
so depending on which version is installed on the build host,
reproducibility issues can occur:
https://bugzilla.yoctoproject.org/show_bug.cgi?id=16072

So far only glibc and grub have been identified to have
the issue; probably more fixes of similar nature will be
required going forward.

Adjust the gawk recipe to apply target-only tweaks
(particularly the removal of awk symlink to allow for alternatives)
to only target and nativesdk variants, so that native installs
both awk and gawk executables.

[YOCTO #16072]

(From OE-Core rev: 288ecfd7d9cd24222cc0f1277105c15cf0889718)

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit c5bbf0a60b1d63e68f849a63e5d3872954e7cd3f)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Bruce Ashfield
3482e7f32a linux-yocto/6.6: address ltp hang
Integrating the following commit(s) to linux-yocto/6.6:

1/1 [
    Author: Baokun Li
    Email: libaokun1@huawei.com
    Subject: ext4: get rid of ppath in get_ext_path()
    Date: Thu, 22 Aug 2024 10:35:32 +0800

    The use of path and ppath is now very confusing, so to make the code more
    readable, pass path between functions uniformly, and get rid of ppath.

    After getting rid of ppath in get_ext_path(), its caller may pass an error
    pointer to ext4_free_ext_path(), so it needs to teach ext4_free_ext_path()
    and ext4_ext_drop_refs() to skip the error pointer. No functional changes.

    Signed-off-by: Baokun Li <libaokun1@huawei.com>
    Reviewed-by: Jan Kara <jack@suse.cz>
    Reviewed-by: Ojaswin Mujoo <ojaswin@linux.ibm.com>
    Tested-by: Ojaswin Mujoo <ojaswin@linux.ibm.com>
    Link: https://patch.msgid.link/20240822023545.1994557-13-libaokun@huaweicloud.com
    Signed-off-by: Theodore Ts'o <tytso@mit.edu>
]

(From OE-Core rev: 737293bead3e7b994347e47f09bc69437479d50c)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
[YC: more detail at https://lore.kernel.org/openembedded-core/DJGKEQF8GRU1.RF7JY64COTAA@smile.fr/T/#u]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
Bruce Ashfield
8cfb09a6b0 linux-yocto/6.6: genericarm64 fix configuration audit warning
Integrating the following commit(s) to linux-yocto/.:

1/1 [
    Author: Bruce Ashfield
    Email: bruce.ashfield@gmail.com
    Subject: genericarm64/serial: change SERIAL_IMX_CONSOLE to =y
    Date: Fri, 19 Jun 2026 00:54:55 +0200

    With the following upstream commit, this option is no longer
    tristate, so we set it to =y instead:

      commit 3f8b835a63341163da0400befb3c6e8f6d4085da
      Author: Randy Dunlap <rdunlap@infradead.org>
      Date:   Sat Jan 10 15:26:40 2026 -0800

          serial: imx: change SERIAL_IMX_CONSOLE to bool

          [ Upstream commit 79527d86ba91c2d9354832d19fd12b3baa66bd10 ]

          SERIAL_IMX_CONSOLE is a build option for the imx driver (SERIAL_IMX).
          It does not build a separate console driver file, so it can't be built
          as a module since it isn't built at all.

          Change the Kconfig symbol from tristate to bool and update the help
          text accordingly.

          Fixes: 0db4f9b91c86 ("tty: serial: imx: enable imx serial console port as module")
          Signed-off-by: Randy Dunlap <rdunlap@infradead.org>
          Link: https://patch.msgid.link/20260110232643.3533351-2-rdunlap@infradead.org
          Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
          Signed-off-by: Sasha Levin <sashal@kernel.org>

    Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
    (cherry picked from commit 465cb5bcefd72f429e0b3ad6ab5b3fcff5b390fc)
    Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
    Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
]

(From OE-Core rev: 535c5940d92c39d220ab2d36b15c2dc31b41b8e0)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
He Zhe
e5db0f30c8 lttng-modules: Fix trace_hrtimer_start build failure
Fix the following build failure

probes/../../include/lttng/tracepoint-event-impl.h:133:6: error: conflicting
types for 'trace_hrtimer_start'; have 'void(struct hrtimer *, enum hrtimer_mode)'
  133 | void trace_##_name(_proto);
      |      ^~~~~~

(From OE-Core rev: e0598e2bbf9513ad71dea185a540de16996c4114)

Signed-off-by: He Zhe <zhe.he@windriver.com>
[YC: backported from wrynose commit e32cbc177dae ("lttng-modules: Fix
trace_hrtimer_start build failure").
This is a partial backport of commit 7dae5f40e394 ("lttng-modules:
fix build against kernel 7.1+")]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
Bruce Ashfield
b61b34f6f8 linux-yocto/6.6: update to v6.6.142
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    924b4a879cbb Linux 6.6.142
    cefa4265b111 security/keys: fix missed RCU read section on lookup
    105c6a594b3f LoongArch: kprobes: Fix handling of fatal unrecoverable recursions
    1f9c82855641 net: gro: don't merge zcopy skbs
    f504118252af pds_core: ensure null-termination for firmware version strings
    d3f3d6fa0cad pds_core: add an error code check in pdsc_dl_info_get
    01f7f893d5e1 net: mana: validate rx_req_idx to prevent out-of-bounds array access
    3dee2fe0c818 ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove()
    d798b25c24f4 gpio: cdev: check if uAPI v2 config attributes are correctly zeroed
    0f1fd5e83f0b gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n)
    cd87492b79d1 string: add mem_is_zero() helper to check if memory area is all zeros
    c9ea01768903 bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
    40fc66218ad1 net: ag71xx: check error for platform_get_irq
    2a1905730e0c Bluetooth: btmtk: fix urb->setup_packet leak in error paths
    f04578422154 Bluetooth: btmtk: move btusb_mtk_hci_wmt_sync to btmtk.c
    73377cf3056a Bluetooth: btmtk: rename btmediatek_data
    aa58d8366269 Bluetooth: btusb: mediatek: refactor the function btusb_mtk_reset
    b748250d778e Bluetooth: btmtk: add the function to get the fw name
    e91687643c44 tracing: Avoid NULL return from hist_field_name() on truncation
    8ba1c4ddbb1c ALSA: seq: Serialize UMP output teardown with event_input
    e5604a480487 ALSA: seq: ump: Use guard() for locking
    b6d3d3816c67 ptrace: Convert ptrace_attach() to use lock guards
    60ef1675b652 pds_core: fix debugfs_lookup dentry leak and error handling
    3231aff8ab26 pds_core: fix error handling in pdsc_devcmd_wait
    1900ca8acb92 bridge: mcast: Fix a possible use-after-free when removing a bridge port
    6e79715b7b8a net: bridge: Flush multicast groups when snooping is disabled
    00904a73272b RDMA/rtrs: Fix use-after-free in path file creation cleanup
    a7685f4d90c1 platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL
    527a7990e663 platform/x86: intel-hid: Check ACPI_HANDLE() against NULL
    6ea1690b24e9 platform/x86: hp_accel: Check ACPI_COMPANION() against NULL
    32ba2ce2b15f platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL
    566f42fb67a7 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
    314a94c47d28 net: dsa: mt7530: preserve VLAN tags on trapped link-local frames
    1bddf306212a net: dsa: mt7530: rename mt753x_bpdu_port_fw enum to mt753x_to_cpu_fw
    d2be607d042d net: dsa: mt7530: fix FDB entries not aging out with short timeout
    69a0885079c9 wifi: ath11k: fix peer resolution on rx path when peer_id=0
    070e40acc59e drm/msm/snapshot: fix dumping of the unaligned regions
    dd844b31f4ea spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache()
    5c54c482934b net/mlx5: Do not restore destination-less TC rules
    d65b279a1898 tls: Preserve sk_err across recvmsg() when data has been copied
    1822997aa8c2 x86/xen: Fix xen_e820_swap_entry_with_ram()
    06cc5ad2c112 net: phy: DP83TC811: add reading of abilities
    d04494596b5e net: phy: c45: add genphy_c45_pma_read_ext_abilities() function
    acdc12b71c9a net: tls: prevent chain-after-chain in plain text SG
    131ef12057d9 net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
    d38ba387244e net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
    a09d07ac45e2 powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()
    7256e54583ae drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
    567b5e976e2e drm/msm/dsi: don't dump registers past the mapped region
    b40e10c72df5 ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics
    720c76b930c5 net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
    9baafc2fea09 accel/qaic: Add overflow check to remap_pfn_range during mmap
    f775be13d342 HID: quirks: really enable the intended work around for appledisplay
    a5db6a7c062f wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm()
    3d675896ea03 wifi: ath11k: fix error path leaks in some WMI WOW calls
    b77be98447c4 net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference
    78cf08b3be47 net: ethernet: cortina: Carry over frag counter
    68c9c3ac9ce5 net: ethernet: cortina: Drop half-assembled SKB
    3b249988d774 net: ethernet: cortina: Make RX SKB per-port
    00efe58bbdcc netfs: Fix overrun check in netfs_extract_user_iter()
    0df68fd72b2a zonefs: handle integer overflow in zonefs_fname_to_fno
    eef4f71b46a9 irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT
    6760af11a26e irqchip/ath79-cpu: Remove unused function
    6af5fd2ffda1 phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access
    b0cc58e8f749 net: lan966x: avoid unregistering netdev on register failure
    9e1c9b957344 ice: fix locking in ice_dcb_rebuild()
    07d77d774f71 tcp: Fix imbalanced icsk_accept_queue count.
    08d355936fcf test_kprobes: clear kprobes between test runs
    8a5f01446021 kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist()
    99948d73a8c7 netfilter: x_tables: unregister the templates first
    26b2290baaf6 btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
    542b49d2cf12 ALSA: hda: cs35l56: Put ACPI device after setting companion
    508b1193d63b ARM: integrator: Fix early initialization
    fb3ff02dd444 pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150
    7d694570281a kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS
    0df3f3031517 kunit: config: Enable KUNIT_DEBUGFS by default
    8b0f4e3b7ad6 firmware: arm_ffa: Skip free_pages on RX buffer alloc failure
    adfff93d08a2 firmware: arm_ffa: Check for NULL FF-A ID table while driver registration
    58ab91af4124 HID: uclogic: Fix regression of input name assignment
    a2d1c819348b hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors
    20d626463e3f hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe()
    cba4f1122dfb hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe()
    6b5573b63e30 hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple
    4d1da9a6be5a hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
    60c4b9fe1a3d hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer
    d94ceb16e55b hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
    f85c81e93dbd hwmon: (pmbus/adm1266) reject implausible blackbox record_count
    025cfc7a09c5 hwmon: (pmbus/adm1266) seed timestamp from the real-time clock
    32edd2a28e11 batman-adv: tt: fix negative tt_buff_len
    22d59c72f4a4 batman-adv: tt: fix negative last_changeset_len
    c2c88736022c batman-adv: tp_meter: fix race condition in send error reporting
    0b1bedf114ea batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
    53f931e0146a batman-adv: tp_meter: avoid use of uninit sender vars
    48663158222b batman-adv: bla: fix report_work leak on backbone_gw purge
    b54e459cf869 batman-adv: frag: disallow unicast fragment in fragment
    c1bac194733a batman-adv: fix tp_meter counter underflow during shutdown
    f653b040dad1 batman-adv: fix fragment reassembly length accounting
    866ac1d57040 batman-adv: dat: handle forward allocation error
    6de089b545db batman-adv: clear current gateway during teardown
    70bcb678561f batman-adv: mcast: fix use-after-free in orig_node RCU release
    90c398e822ca drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async
    fb30a3890d62 drm/amd/display: Validate GPIO pin LUT table size before iterating
    266b21b57fbb drm/amd/display: Fix integer overflow in bios_get_image()
    e4d3d33ab7bd drm/bridge: megachips: remove bridge when irq request fails
    25473edcdaef drm/bridge: it66121: acquire reset GPIO in probe
    21ab64c77a30 drm/virtio: use uninterruptible resv lock for plane updates
    371f53925a67 device property: set fwnode->secondary to NULL in fwnode_init()
    fb3539b367f5 LoongArch: Remove unused code to avoid build warning
    14553be882d9 RDMA/siw: Reject MPA FPDU length underflow before signed receive math
    f2dc841d7dc9 spi: ti-qspi: fix use-after-free after DMA setup failure
    450c319dd04d spi: sprd: fix error pointer deref after DMA setup failure
    309c6058622d scsi: isci: Fix use-after-free in device removal path
    9d5ae6b8d9ec phy: tegra: xusb: Fix per-pad high-speed termination calibration
    45760b72e84c spi: qup: fix error pointer deref after DMA setup failure
    3c83a6912c24 drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe
    dab9f93251b2 KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits
    e0790046f6be arm64: probes: Handle probes on hinted conditional branch instructions
    f383cff9fb38 tracing: Do not call map->ops->elt_free() if elt_alloc() fails
    bdc349a87f1f cifs: Fix busy dentry used after unmounting
    1ced0f5a851f wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
    a3a4366731a5 ice: fix setting promisc mode while adding VID filter
    add70e2682c0 ixgbevf: fix use-after-free in VEPA multicast source pruning
    3c5411fa4944 ipv4: raw: reject IP_HDRINCL packets with ihl < 5
    f50c3ff97c83 wifi: ath11k: clear shared SRNG pointer state on restart
    ce29d3bf79a2 vsock/virtio: reset connection on receiving queue overflow
    cc27e989a5df vsock/vmci: fix UAF when peer resets connection during handshake
    273a1481c556 ring-buffer: Fix reporting of missed events in iterator
    3904b993cc17 qed: fix double free in qed_cxt_tables_alloc()
    c161ad9157f5 netfilter: nft_inner: Fix IPv6 inner_thoff desync
    c281e018af98 netfilter: ipset: stop hash:* range iteration at end
    1e5e20031c5e netfilter: nf_queue: hold bridge skb->dev while queued
    41ec2e242f17 netfilter: ip6t_hbh: reject oversized option lists
    16bd798cb6d8 net: ifb: report ethtool stats over num_tx_queues
    289499907399 net: bcmgenet: keep RBUF EEE/PM disabled
    8420aa490041 phonet/pep: disable BH around forwarded sk_receive_skb()
    be43e6b40431 Bluetooth: serialize accept_q access
    a143ce77a529 Bluetooth: MGMT: validate Add Extended Advertising Data length
    9d20d48be2c4 Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
    fe69f634b076 Bluetooth: bnep: Fix UAF read of dev->name
    3af41ee7ebec Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
    5d86d2f1b4d9 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
    6f63a60580eb net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
    686b4283f82c drivers/base/memory: fix memory block reference leak in poison accounting
    29cd94e678fc efi: Allocate runtime workqueue before ACPI init
    7b6f8c8eb93f ALSA: asihpi: Fix potential OOB array access at reading cache
    41a766c64729 ALSA: pcm: Don't setup bogus iov_iter for silencing
    dade81458966 ALSA: ua101: Reject too-short USB descriptors
    0dbf64c50244 hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
    adcfb16ae402 smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close
    7df1df6f40c0 smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
    9d378e17c864 ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
    e43cb36d4d78 ksmbd: fix null pointer dereference in compare_guid_key()
    082351f9d400 mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()
    31527d80234c sysfs: don't remove existing directory on update failure
    ad7520628c74 Revert "af_unix: Reject SIOCATMARK on non-stream sockets"
    f624070c322d Revert "s390/cio: Update purge function to unregister the unused subchannels"
    7963b6141b4c Revert "ice: Remove jumbo_remove step from TX path"
    6331b0f7b71e Revert "ice: fix double-free of tx_buf skb"
    2035acfb1722 smb: client: reject userspace cifs.spnego descriptions
    3106f326f67c af_unix: Give up GC if MSG_PEEK intervened.
    3a436932eb39 ksmbd: close durable scavenger races against m_fp_list lookups
    712cdf917e77 ksmbd: validate owner of durable handle on reconnect
    7f0cb478703c ksmbd: add durable scavenger timer
    50a23fa28e76 ksmbd: avoid reclaiming expired durable opens by the client
    2682bf9a804b Revert "x86/vdso: Fix output operand size of RDPID"
    ba5b43db126a wifi: mac80211: check tdls flag in ieee80211_tdls_oper
    a052c2d8399a s390/debug: Reject zero-length input before trimming a newline
    492349e5e4a3 driver core: platform: use generic driver_override infrastructure
    64a3ee535bd7 driver core: generalize driver_override in struct device
    fabfed1afe27 spi: spidev: fix lock inversion between spi_lock and buf_lock
    6a3af482188f mptcp: pm: ADD_ADDR rtx: free sk if last
    9426265e157d mptcp: pm: ADD_ADDR rtx: always decrease sk refcount
    19a3ec9ef176 mptcp: pm: ADD_ADDR rtx: allow ID 0
    b386aa38b81d mptcp: sync the msk->sndbuf at accept() time

(From OE-Core rev: ba0f120f6cdbcc1d2782bef27c101e20a11f0f19)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00