On Mon Jul 6, 2026 at 6:17 PM CEST, Yoann Congal wrote: > On Mon Jun 8, 2026 at 4:07 PM CEST, J?r?my Rosen via lists.openembedded.org > wrote: >> Hello Jackson >> >> from what I see all the CVE are not applied to the upper branches of >> yocto >> >> CVE-2026-5450 is applied to master but not wrynose >> CVE-2026-5928 is not applied, neither to master nor wrynose. >> >> The other three CVE seem to be backported correctly >> >> please submit for master/wrynose and the resubmit for scarthgap > > Hello Jackson, > > Gentle ping for this patch needing patches for more recent branches. > Also: > * Please put the CVE id in the patch titles "Fix CVEs" is a bit too > vague. > * glibc CVEs are usualy handled via upgrades along the stable branch > instead of backporting individual patches. > * Nitpick: the CVE patches are usualy simply named "CVE-XXX-YYYY.patch"
I will now drop this patch in favor of the glibc upgrade patch received in the meantime. Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#241282): https://lists.openembedded.org/g/openembedded-core/message/241282 Mute This Topic: https://lists.openembedded.org/mt/119542722/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
