mirror of
https://git.yoctoproject.org/poky
synced 2026-07-23 04:17:46 +02:00
Backport the upstream 3-commit fix chain for CVE-2026-5704. The final CVE fix is [1], which depends on the earlier cleanup in [2] and the behavioral change in [3]. Keep this patch order so the final fix applies cleanly and preserves the upstream logic. Also include upstream follow-up [4] to fix the --no-overwrite-dir ptest regression caused by the CVE backport. Without this follow-up, tar can temporarily chmod an existing directory even when --no-overwrite-dir is used, which breaks the upstream --no-overwrite-dir ptest. [1] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=b8d8a61b25588caca4efaf9bdd2e3f1a49da77e3 [2] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=112ead79312ea308e58414b74623f101b8c06f0b [3] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=b009124ffde415515081db844d7a104e1d1c6c58 [4] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=4e742fc8674064a9fa00d4483d06aca48d5b0463 [5] https://security-tracker.debian.org/tracker/CVE-2026-5704 (From OE-Core rev: 86360db7d1ea4e5d2bac9889cf8fefe6148a90b4) Signed-off-by: Himanshu Jadon <hjadon@cisco.com> Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit 872d86b99ad3e77a105b386331a41f7fa40c2b72) Signed-off-by: Himanshu Jadon <hjadon@cisco.com> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>