Please review this set of patches for dunfell and have comments back by end of day Tuesday.
Passed a-full on autobuilder: https://autobuilder.yoctoproject.org/typhoon/#/builders/83/builds/4715 The following changes since commit cc8ec63310f9a936371ea1070cb257c926808755: oeqa/selftest/tinfoil: Add test for separate config_data with recipe_parse_file() (2022-12-14 16:34:29 -1000) are available in the Git repository at: https://git.openembedded.org/openembedded-core-contrib stable/dunfell-nut http://cgit.openembedded.org/openembedded-core-contrib/log/?h=stable/dunfell-nut Alexander Kanavin (1): tzdata: update 2022d -> 2022g Bruce Ashfield (4): linux-yocto/5.4: update to v5.4.221 linux-yocto/5.4: update to v5.4.224 linux-yocto/5.4: update to v5.4.225 linux-yocto/5.4: update to v5.4.228 Chen Qi (1): bc: extend to nativesdk Hitendra Prajapati (1): grub2: CVE-2022-28735 shim_lock verifier allows non-kernel files to be loaded Jagadeesh Krishnanjanappa (1): qemuboot.bbclass: make sure runqemu boots bundled initramfs kernel image Joshua Watt (1): sudo: Use specific BSD license variant Minjae Kim (1): ppp: fix CVE-2022-4603 Peter Marko (1): externalsrc: fix lookup for .gitmodules Quentin Schulz (1): cairo: update patch for CVE-2019-6461 with upstream solution Robert Andersson (1): go-crosssdk: avoid host contamination by GOCACHE Ross Burton (1): lib/buildstats: fix parsing of trees with reduced_proc_pressure directories Vivek Kumbhar (4): go: fix CVE-2022-41717 Excessive memory use in got server rsync: fix CVE-2022-29154 remote arbitrary files write inside the directories of connecting peers libx11: fix CVE-2022-3555 memory leak in _XFreeX11XCBStructure() of xcb_disp.c qemu: fix CVE-2021-3507 fdc heap buffer overflow in DMA read data transfers meta/classes/externalsrc.bbclass | 2 +- meta/classes/qemuboot.bbclass | 3 +- .../grub/files/CVE-2022-28735.patch | 271 ++++++++++++++ meta/recipes-bsp/grub/grub2.inc | 1 + .../ppp/ppp/CVE-2022-4603.patch | 50 +++ meta/recipes-connectivity/ppp/ppp_2.4.7.bb | 1 + meta/recipes-devtools/go/go-1.14.inc | 1 + .../go/go-1.14/CVE-2022-41717.patch | 75 ++++ meta/recipes-devtools/go/go-crosssdk.inc | 2 + meta/recipes-devtools/qemu/qemu.inc | 1 + .../qemu/qemu/CVE-2021-3507.patch | 87 +++++ .../rsync/files/CVE-2022-29154.patch | 334 ++++++++++++++++++ meta/recipes-devtools/rsync/rsync_3.1.3.bb | 1 + meta/recipes-extended/bc/bc_1.07.1.bb | 2 +- meta/recipes-extended/sudo/sudo.inc | 2 +- meta/recipes-extended/timezone/timezone.inc | 7 +- .../cairo/cairo/CVE-2019-6461.patch | 35 +- .../xorg-lib/libx11/CVE-2022-3555.patch | 38 ++ .../recipes-graphics/xorg-lib/libx11_1.6.9.bb | 1 + .../linux/linux-yocto-rt_5.4.bb | 6 +- .../linux/linux-yocto-tiny_5.4.bb | 8 +- meta/recipes-kernel/linux/linux-yocto_5.4.bb | 22 +- scripts/lib/buildstats.py | 4 +- 23 files changed, 919 insertions(+), 35 deletions(-) create mode 100644 meta/recipes-bsp/grub/files/CVE-2022-28735.patch create mode 100644 meta/recipes-connectivity/ppp/ppp/CVE-2022-4603.patch create mode 100644 meta/recipes-devtools/go/go-1.14/CVE-2022-41717.patch create mode 100644 meta/recipes-devtools/qemu/qemu/CVE-2021-3507.patch create mode 100644 meta/recipes-devtools/rsync/files/CVE-2022-29154.patch create mode 100644 meta/recipes-graphics/xorg-lib/libx11/CVE-2022-3555.patch -- 2.25.1
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#175218): https://lists.openembedded.org/g/openembedded-core/message/175218 Mute This Topic: https://lists.openembedded.org/mt/95992300/21656 Group Owner: openembedded-core+ow...@lists.openembedded.org Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [arch...@mail-archive.com] -=-=-=-=-=-=-=-=-=-=-=-