On Wed Jul 15, 2026 at 7:21 PM CEST, Deepak Rathore via lists.openembedded.org wrote: > From: Deepak Rathore <[email protected]> > > This patch applies the upstream 2.88.1 backport for > CVE-2026-58010. The upstream fix commit is referenced in [1], > and the public CVE advisory is referenced in [2]. > > [1] > https://gitlab.gnome.org/GNOME/glib/-/commit/be85f9429bb66412a9775440a88cb115803ba897 > [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58010 > > Signed-off-by: Deepak Rathore <[email protected]>
Hello Deepak and Adarsh, You both sent backport patches for this CVE. This CVE (and I bet others of this series) can be fixed by upgrading along the 2.88.x branch of glib. There are precedent for glib upgrade on stable branches. Can you look into the glib changelog and see if there are changes incompatible with our policy? If upgrading is compatible, please tell me and I will cherry pick the upgrades from master: glib-2.0: Upgrade 2.88.0 -> 2.88.1 https://git.openembedded.org/openembedded-core/commit/?id=e2063c252d1ab3188e74e9eced91bc17463d6551 glib-2.0: upgrade 2.88.1 -> 2.88.2 https://git.openembedded.org/openembedded-core/commit/?id=c22a7bd7ecb463da212c25a5aa81a19992e17e1c If not, ping me as well, I will then resume reviewing this series. Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#241207): https://lists.openembedded.org/g/openembedded-core/message/241207 Mute This Topic: https://lists.openembedded.org/mt/120285725/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
