Please review this set of patches for kirkstone and have comments back by end of day Tuesday.
Passed a-full on autobuilder: https://autobuilder.yoctoproject.org/typhoon/#/builders/83/builds/5185 The following changes since commit ff4b57ffff903a93b710284c7c7f916ddd74712f: uninative: Upgrade to 3.9 to include glibc 2.37 (2023-04-04 05:32:01 -1000) are available in the Git repository at: https://git.openembedded.org/openembedded-core-contrib stable/kirkstone-nut http://cgit.openembedded.org/openembedded-core-contrib/log/?h=stable/kirkstone-nut Hitendra Prajapati (2): curl: CVE-2023-27533 TELNET option IAC injection curl: CVE-2023-27534 SFTP path resolving discrepancy Joe Slater (1): go: fix CVE-2022-41724, 41725 Mark Hatle (1): openssl: Move microblaze to linux-latomic config Pawan Badganchi (1): tiff: Add fix for CVE-2022-4645 Peter Marko (1): package.bbclass: correct check for /build in copydebugsources() Yash Shinde (1): binutils : Fix CVE-2023-1579 meta/classes/package.bbclass | 2 +- .../openssl/openssl_3.0.8.bb | 4 +- .../binutils/binutils-2.38.inc | 4 + .../binutils/0021-CVE-2023-1579-1.patch | 459 ++++ .../binutils/0021-CVE-2023-1579-2.patch | 2127 +++++++++++++++ .../binutils/0021-CVE-2023-1579-3.patch | 156 ++ .../binutils/0021-CVE-2023-1579-4.patch | 37 + meta/recipes-devtools/go/go-1.17.13.inc | 5 +- .../go/go-1.19/add_godebug.patch | 84 + .../go/go-1.19/cve-2022-41724.patch | 2391 +++++++++++++++++ .../go/go-1.19/cve-2022-41725.patch | 652 +++++ ...-of-TIFFTAG_INKNAMES-and-related-TIF.patch | 5 +- .../curl/curl/CVE-2023-27533.patch | 208 ++ .../curl/curl/CVE-2023-27534.patch | 122 + meta/recipes-support/curl/curl_7.82.0.bb | 2 + 15 files changed, 6252 insertions(+), 6 deletions(-) create mode 100644 meta/recipes-devtools/binutils/binutils/0021-CVE-2023-1579-1.patch create mode 100644 meta/recipes-devtools/binutils/binutils/0021-CVE-2023-1579-2.patch create mode 100644 meta/recipes-devtools/binutils/binutils/0021-CVE-2023-1579-3.patch create mode 100644 meta/recipes-devtools/binutils/binutils/0021-CVE-2023-1579-4.patch create mode 100644 meta/recipes-devtools/go/go-1.19/add_godebug.patch create mode 100644 meta/recipes-devtools/go/go-1.19/cve-2022-41724.patch create mode 100644 meta/recipes-devtools/go/go-1.19/cve-2022-41725.patch create mode 100644 meta/recipes-support/curl/curl/CVE-2023-27533.patch create mode 100644 meta/recipes-support/curl/curl/CVE-2023-27534.patch -- 2.34.1
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#180010): https://lists.openembedded.org/g/openembedded-core/message/180010 Mute This Topic: https://lists.openembedded.org/mt/98283665/21656 Group Owner: openembedded-core+ow...@lists.openembedded.org Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [arch...@mail-archive.com] -=-=-=-=-=-=-=-=-=-=-=-