This mail was sent out by Recipe reporting system. This message list those recipes which need to be upgraded. If maintainers believe some of them needn't to upgrade at this time, they can fill RECIPE_NO_UPDATE_REASON in respective recipe file to ignore this remainder until newer upstream version was detected.
Example: RECIPE_NO_UPDATE_REASON = "Version 2.0 is unstable" You can check the detail information at: http://recipes.yoctoproject.org/ Package Version Upstream version Maintainer NoUpgradeReason -------------------- --------------- -------------------- ------------------- ------------------------------ eudev 3.2.2 3.2.5 Alejandro Hernandez epiphany 3.24.3 3.26.5.1 Alexander Kanavin usbutils 008 009 Alexander Kanavin systemtap 3.1 3.2 Alexander Kanavin gtk-doc 1.25 1.27 Alexander Kanavin trace-cmd 2.6.1 2.6.2 Alexander Kanavin vala 0.38.2 0.38.4 Alexander Kanavin libwebp 0.6.0 0.6.1 Alexander Kanavin libnl 3.2.29 3.4.0 Alexander Kanavin ffmpeg 3.4 3.4.1 Alexander Kanavin gdbm 1.13 1.14.1 Alexander Kanavin blktrace 1.1.0+gitX 1.2.0 Alexander Kanavin bjam-native 1.65.1 1.66.0 Alexander Kanavin boost 1.65.1 1.66.0 Alexander Kanavin btrfs-tools 4.13.3 4.14.1 Alexander Kanavin systemtap-uprobes 3.1 3.2 Alexander Kanavin kernelshark 2.6.1 2.6.2 Alexander Kanavin mpg123 1.25.7 1.25.8 Alexander Kanavin iso-codes 3.76 3.77 Alexander Kanavin tiff 4.0.8 4.0.9 Alexander Kanavin icu 60.1 60.2 Alexander Kanavin apt 1.2.24 1.4.8 Aníbal Limón apt-native 1.2.24 1.4.8 Aníbal Limón dpkg 1.18.24 1.19.0.4 Aníbal Limón bind 9.10.6 9.11.2 Armin Kuster curl 7.54.1 7.57.0 Armin Kuster busybox 1.27.2 1.28.0 Armin Kuster linux-libc-headers 4.12 4.14.13 Bruce Ashfield libunwind 1.2 1.2.1 Bruce Ashfield iproute2 4.13.0 4.14.1 Changhyeok Bae iw 4.9 4.14 Changhyeok Bae kmod-native 24+gitX 25 Chen Qi systemd 234 236 Chen Qi util-linux 2.31 2.31.1 Chen Qi kmod 24+gitX 25 Chen Qi sed 4.2.2 4.4 Chen Qi sysstat 11.6.1 11.7.1 Chen Qi tar 1.29 1.30 Chen Qi systemd-boot 234 236 Chen Qi systemd-bootchart 231+gitX 233 Chen Qi flex 2.6.0 2.6.4 Chen Qi build-appliance-i... 15.0.0 18.0.1 Cristian Iorga hdparm 9.52 9.53 Denys Dmytriyenko lz4 1.7.4 1.8.1.2 Denys Dmytriyenko lzop 1.03 1.04 Denys Dmytriyenko gzip 1.8 1.9 Denys Dmytriyenko mtd-utils 2.0.0 2.0.1 Denys Dmytriyenko python-numpy 1.13.1 1.14.0rc1 Derek Straka python 2.7.13 2.7.14 Derek Straka python3-setuptools 38.2.5 38.4.0 Derek Straka python-setuptools 38.2.5 38.4.0 Derek Straka python3-numpy 1.13.3 1.14.0rc1 Derek Straka python3-native 3.5.3 3.6.4 Derek Straka python-native 2.7.13 2.7.14 Derek Straka python3 3.5.3 3.6.4 Derek Straka acpica 20170303 20180105 Fathi Boudra ncurses 6.0+20170715 6.0+20171125 Hongxu Jia gpgme 1.9.0 1.10.0 Hongxu Jia bash 4.4 4.4.12 Hongxu Jia ghostscript 9.21 9.22 Hongxu Jia man-pages 4.11 4.14 Hongxu Jia apr-util 1.6.0 1.6.1 Hongxu Jia pigz 2.3.4 2.4 Hongxu Jia help2man-native 1.47.4 1.47.5 Hongxu Jia apr 1.6.2 1.6.3 Hongxu Jia bc 1.06 1.07.1 Jose Lamego pango 1.40.12 1.40.14 Jussi Kukkonen piglit 1.0+gitrX 1.0-new-commits-a... Jussi Kukkonen libinput 1.8.4 1.9.4 Jussi Kukkonen vulkan-demos git git-new-commits-a... Jussi Kukkonen gtk-icon-utils-na... 3.22.17 3.22.26 Jussi Kukkonen libsoup-2.4 2.60.2 2.60.3 Jussi Kukkonen puzzles 0.0+gitX 0.0-new-commits-a... Jussi Kukkonen atk 2.26.0 2.26.1 Jussi Kukkonen glib-2.0 2.54.2 2.54.3 Jussi Kukkonen vte 0.50.1 0.50.2 Jussi Kukkonen vulkan 1.0.61.1 1.0.65.2 Jussi Kukkonen assimp 4.0.1 4.1.0 Jussi Kukkonen adwaita-icon-theme 3.26.0 3.26.1 Jussi Kukkonen gtk+3 3.22.24 3.22.26 Jussi Kukkonen gtk+ 2.24.31 2.24.32 Jussi Kukkonen librsvg 2.40.19 2.42.0 Jussi Kukkonen fontconfig 2.12.6 2.12.91 Jussi Kukkonen freetype 2.8.1 2.9 Jussi Kukkonen cross-localedef-n... 2.26 2.26.9000 Khem Raj glibc-initial 2.26 2.26.9000 Khem Raj ninja 1.7.2 1.8.2 Khem Raj mpfr 3.1.5 4.0.0 Khem Raj re2c 0.16 1.0.1 Khem Raj go-native 1.9 1.10beta2 Khem Raj go 1.9 1.10beta2 Khem Raj libnsl2 1.0.5+gitX 1.2.0 Khem Raj llvm 5.0 5.0-new-commits-a... Khem Raj glibc 2.26 2.26.9000 Khem Raj liburi-perl 1.72 1.73 Leonardo Sandoval perl 5.24.1 5.26.1 Leonardo Sandoval ruby 2.4.2 2.5.0 Leonardo Sandoval nfs-utils 2.1.1 2.3.1 Leonardo Sandoval qemu 2.10.1 2.11.0 Leonardo Sandoval perl-native 5.24.1 5.26.1 Leonardo Sandoval u-boot-fw-utils 2017.11 2018.01 Marek Vasut u-boot-mkimage 2017.11 2018.01 Marek Vasut u-boot 2017.11 2018.01 Marek Vasut ifupdown 0.8.16 0.8.29 Maxin B. John libical 2.0.0 3.0.1 Maxin B. John gst-examples 0.0.1+gitX 0.0.1-new-commits... Maxin B. John libsolv 0.6.29 0.6.30 Maxin B. John screen 4.6.1 4.6.2 Maxin B. John pkgconf 1.3.7 1.4.0 Maxin B. John i2c-tools 3.1.2 4.0 Maxin B. John go-crosssdk-x86_64 1.9 1.10beta2 No maintainer systemtap-native 3.1 3.2 No maintainer go-cross-i586 1.9 1.10beta2 No maintainer go-runtime 1.9 1.10beta2 No maintainer go-cross-canadian... 1.9 1.10beta2 No maintainer cmake 3.9.5 3.10.1 Otavio Salvador cmake-native 3.9.5 3.10.1 Otavio Salvador go-dep 0.3.1 0.3.2 Otavio Salvador libdrm 2.4.88 2.4.89 Otavio Salvador tcf-agent 1.4.0+gitX 1.6.0 Randy Witt build-compare 2015.02.10+gitX 2015.02.10-new-co... Randy Witt subversion 1.9.6 1.9.7 Richard Purdie lttng-tools 2.9.5 2.10.1 Richard Purdie lttng-ust 2.9.1 2.10.1 Richard Purdie lttng-modules 2.9.5 2.10.4 Richard Purdie nasm 2.13.01 2.13.02 Richard Purdie gnu-config 20150728+gitX 20150728-new-comm... Robert Yang debianutils 4.8.1.1 4.8.4 Robert Yang squashfs-tools 4.3+gitrX 4.3-new-commits-a... Robert Yang strace 4.19 4.20 Robert Yang e2fsprogs 1.43.7 1.43.8 Robert Yang autoconf-archive 2016.09.16 2017.09.28 Robert Yang less 527 529 Robert Yang tcl 8.6.7 8.6.8 Robert Yang ccache 3.3.4 3.3.5 Robert Yang time 1.7 1.8 Robert Yang git 2.15.0 2.15.1 Robert Yang base-passwd 3.5.29 3.5.44 Ross Burton Version 3.5.38 requires cde... lsbinitscripts 9.72 9.79 Ross Burton libva-utils 1.8.3 2.0.0 Wei Tee Ng libva 1.8.3 2.0.0 Wei Tee Ng chkconfig 1.3.58 1.8 Yi Zhao Version 1.5 requires selinux json-glib 1.2.8 1.4.2 Yi Zhao Upgradable count: 141 Upgradable total count: 143 The based commit is: commit 92a0513837182e2e9aa6c7d4958e495f4b5b4c47 Author: Catalin Enache <catalin.ena...@windriver.com> Date: Tue Dec 19 12:39:12 2017 +0200 qemu: CVE-2017-17381 The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process crash) by unsetting vring alignment while updating Virtio rings. Reference: https://nvd.nist.gov/vuln/detail/CVE-2017-17381 Upstream patch: https://git.qemu.org/?p=qemu.git;a=commitdiff;h=758ead31c7e17bf17a9ef2e0ca1c3e86ab296b43 Signed-off-by: Catalin Enache <catalin.ena...@windriver.com> Signed-off-by: Ross Burton <ross.bur...@intel.com> Any problem, please contact Jose Lamego <jose.a.lam...@intel.com> -- _______________________________________________ yocto mailing list yocto@yoctoproject.org https://lists.yoctoproject.org/listinfo/yocto