On Mon Jul 6, 2026 at 6:17 PM CEST, Yoann Congal wrote:
> On Mon Jun 8, 2026 at 4:07 PM CEST, J?r?my Rosen via lists.openembedded.org 
> wrote:
>> Hello Jackson
>>
>> from what I see all the CVE are not applied to the upper branches of
>> yocto
>>
>> CVE-2026-5450 is applied to master but not wrynose
>> CVE-2026-5928 is not applied, neither to master nor wrynose.
>>
>> The other three CVE seem to be backported correctly
>>
>> please submit for master/wrynose and the resubmit for scarthgap
>
> Hello Jackson,
>
> Gentle ping for this patch needing patches for more recent branches.
> Also:
> * Please put the CVE id in the patch titles "Fix CVEs" is a bit too
>   vague.
> * glibc CVEs are usualy handled via upgrades along the stable branch
>   instead of backporting individual patches.
> * Nitpick: the CVE patches are usualy simply named "CVE-XXX-YYYY.patch"

I will now drop this patch in favor of the glibc upgrade patch received
in the meantime.

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#241282): 
https://lists.openembedded.org/g/openembedded-core/message/241282
Mute This Topic: https://lists.openembedded.org/mt/119542722/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to