Please review this set of changes for dunfell and have comments back by end of day Tuesday, October 3
Passed a-full on autobuilder: https://autobuilder.yoctoproject.org/typhoon/#/builders/83/builds/5966 The following changes since commit a9d194f21a3bdebca8aaff204804a5fdc67c76d1: vim: Upgrade 9.0.1664 -> 9.0.1894 (2023-09-25 07:03:13 -1000) are available in the Git repository at: https://git.openembedded.org/openembedded-core-contrib stable/dunfell-nut http://cgit.openembedded.org/openembedded-core-contrib/log/?h=stable/dunfell-nut Alexander Kanavin (1): nasm: update 2.15.03 -> 2.15.05 Archana Polampalli (1): nasm: fix CVE-2022-44370 Ashish Sharma (1): mdadm: Backport fix for CVE-2023-28736 Bruce Ashfield (4): linux-yocto/5.4: update to v5.4.252 linux-yocto/5.4: update to v5.4.254 linux-yocto/5.4: update to v5.4.256 linux-yocto/5.4: update to v5.4.257 Colin McAllister (1): libwebp: Fix CVE-2023-5129 Lee Chee Yang (3): libxpm: fix CVE-2022-46285 qemu: fix CVE-2020-24165 python3: update to 3.8.18 Siddharth Doshi (1): go: Fix CVE-2023-39318 and CVE-2023-39319 Vijay Anusuri (1): ghostscript: fix CVE-2023-36664 meta/recipes-devtools/go/go-1.14.inc | 2 + .../go/go-1.14/CVE-2023-39318.patch | 238 ++++++++++++ .../go/go-1.14/CVE-2023-39319.patch | 230 +++++++++++ .../0002-Add-debug-prefix-map-option.patch | 42 +- .../nasm/nasm/CVE-2022-44370.patch | 104 +++++ .../nasm/{nasm_2.15.03.bb => nasm_2.15.05.bb} | 5 +- .../{python3_3.8.17.bb => python3_3.8.18.bb} | 4 +- meta/recipes-devtools/qemu/qemu.inc | 1 + .../qemu/qemu/CVE-2020-24165.patch | 94 +++++ .../ghostscript/CVE-2023-36664-1.patch | 145 +++++++ .../ghostscript/CVE-2023-36664-2.patch | 60 +++ .../ghostscript/CVE-2023-36664-pre1.patch | 62 +++ .../ghostscript/ghostscript_9.52.bb | 3 + .../mdadm/files/CVE-2023-28736.patch | 77 ++++ meta/recipes-extended/mdadm/mdadm_4.1.bb | 1 + .../xorg-lib/libxpm/CVE-2022-46285.patch | 40 ++ .../xorg-lib/libxpm_3.5.13.bb | 2 + .../linux/linux-yocto-rt_5.4.bb | 6 +- .../linux/linux-yocto-tiny_5.4.bb | 8 +- meta/recipes-kernel/linux/linux-yocto_5.4.bb | 22 +- .../webp/files/CVE-2023-5129.patch | 364 ++++++++++++++++++ meta/recipes-multimedia/webp/libwebp_1.1.0.bb | 1 + 22 files changed, 1467 insertions(+), 44 deletions(-) create mode 100644 meta/recipes-devtools/go/go-1.14/CVE-2023-39318.patch create mode 100644 meta/recipes-devtools/go/go-1.14/CVE-2023-39319.patch create mode 100644 meta/recipes-devtools/nasm/nasm/CVE-2022-44370.patch rename meta/recipes-devtools/nasm/{nasm_2.15.03.bb => nasm_2.15.05.bb} (80%) rename meta/recipes-devtools/python/{python3_3.8.17.bb => python3_3.8.18.bb} (99%) create mode 100644 meta/recipes-devtools/qemu/qemu/CVE-2020-24165.patch create mode 100644 meta/recipes-extended/ghostscript/ghostscript/CVE-2023-36664-1.patch create mode 100644 meta/recipes-extended/ghostscript/ghostscript/CVE-2023-36664-2.patch create mode 100644 meta/recipes-extended/ghostscript/ghostscript/CVE-2023-36664-pre1.patch create mode 100644 meta/recipes-extended/mdadm/files/CVE-2023-28736.patch create mode 100644 meta/recipes-graphics/xorg-lib/libxpm/CVE-2022-46285.patch create mode 100644 meta/recipes-multimedia/webp/files/CVE-2023-5129.patch -- 2.34.1
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#188465): https://lists.openembedded.org/g/openembedded-core/message/188465 Mute This Topic: https://lists.openembedded.org/mt/101681322/21656 Group Owner: openembedded-core+ow...@lists.openembedded.org Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [arch...@mail-archive.com] -=-=-=-=-=-=-=-=-=-=-=-