meta-openembedded: Merge latest upstream#122
Open
Shreejit-03 wants to merge 30 commits into
Open
Conversation
Ignore CVE-2025-14821 as it is only applicable for windows. Reference: [https://security-tracker.debian.org/tracker/CVE-2025-14821] Signed-off-by: Naman Jain <naman.jain@partner.bmw.de> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Apply the nearest upstream fix from v1.62.3 [1] for HPACK parser error handling to prevent header table desynchronization, aligned with the original fix in v1.60.2 [2] as referenced in [3]. [1] grpc/grpc@1d172cf [2] grpc/grpc@88b1244 [3] https://bugzilla.suse.com/show_bug.cgi?id=1228919 References: https://nvd.nist.gov/vuln/detail/CVE-2024-7246 Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
The vulnerability only affects the Go implementation of the library, not the Python one. Ignore this CVE due to this. Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33186 Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Set correct CVE_PRODUCT for paramiko. The default python:paramiko value doesn't match CVEs, because the product has its own set of CPEs associated with CVEs. See CVE db query: sqlite> select * from products where PRODUCT = 'paramiko'; CVE-2008-0299|python_software_foundation|paramiko|1.7.1|=|| CVE-2018-1000805|paramiko|paramiko|1.17.6|=|| CVE-2018-1000805|paramiko|paramiko|1.18.5|=|| CVE-2018-1000805|paramiko|paramiko|2.0.8|=|| CVE-2018-1000805|paramiko|paramiko|2.1.5|=|| CVE-2018-1000805|paramiko|paramiko|2.2.3|=|| CVE-2018-1000805|paramiko|paramiko|2.3.2|=|| CVE-2018-1000805|paramiko|paramiko|2.4.1|=|| CVE-2018-7750|paramiko|paramiko|||1.17.6|< CVE-2018-7750|paramiko|paramiko|1.18.0|>=|1.18.5|< CVE-2018-7750|paramiko|paramiko|2.0.0|>=|2.0.8|< CVE-2018-7750|paramiko|paramiko|2.1.0|>=|2.1.5|< CVE-2018-7750|paramiko|paramiko|2.2.0|>=|2.2.3|< CVE-2018-7750|paramiko|paramiko|2.3.0|>=|2.3.2|< CVE-2018-7750|paramiko|paramiko|2.4.0|=|| CVE-2022-24302|paramiko|paramiko|||2.10.1|< CVE-2023-48795|paramiko|paramiko|||3.4.0|< Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit e22d2a7) Signed-off-by: Himanshu Jadon <hjadon@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Set CVE_PRODUCT to the value that is used to track CVEs for this recipe in the CVE db. See CVE db query (priority-software vendor is not relevant): sqlite> select * from products where product like '%priority%'; CVE-2016-6580|python|python_priority_library|1.0.0|=|| CVE-2016-6580|python|python_priority_library|1.1.0|=|| CVE-2016-6580|python|python_priority_library|1.1.1|=|| CVE-2021-26832|priority-software|priority_enterprise_management_system|8.00|=|| CVE-2022-23172|priority-software|priority|||22.0|< CVE-2022-23173|priority-software|priority|||22.0|< CVE-2023-23459|priority-software|priority|||22.1|< CVE-2023-23460|priority-software|priority|19.1.0.68|=|| CVE-2024-41697|priority-software|priority|||24.0|< CVE-2024-41698|priority-software|priority|||24.0|< CVE-2024-41699|priority-software|priority|||24.0|< Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 96c3818) Signed-off-by: Himanshu Jadon <hjadon@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Set correct CVE_PRODUCT - the default ${PN} value doesn't match relevant
CVEs.
See CVE query (n8n vendor is not relevant):
sqlite> select * from products where product like '%pydantic%';
CVE-2021-29510|pydantic|pydantic|||1.6.2|<
CVE-2021-29510|pydantic|pydantic|1.7|>=|1.7.4|<
CVE-2021-29510|pydantic|pydantic|1.8|>=|1.8.2|<
CVE-2024-3772|pydantic|pydantic|||1.10.13|<
CVE-2024-3772|pydantic|pydantic|2.0|>=|2.4.0|<
CVE-2025-55526|n8n|pydantic|2.11.7|=||
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit b4fd4a6)
Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This recipe's CVEs are tracked using supervisord:supervisor CPE by nist, so the default python:supervisor CPE doesn't match relevant CVEs. See CVE db query (home-assisstant vendor is not relevant): sqlite> select * from products where PRODUCT like 'supervisor'; CVE-2017-11610|supervisord|supervisor|||3.0|<= CVE-2017-11610|supervisord|supervisor|3.1.0|=|| CVE-2017-11610|supervisord|supervisor|3.1.1|=|| CVE-2017-11610|supervisord|supervisor|3.1.2|=|| CVE-2017-11610|supervisord|supervisor|3.1.3|=|| CVE-2017-11610|supervisord|supervisor|3.2.0|=|| CVE-2017-11610|supervisord|supervisor|3.2.1|=|| CVE-2017-11610|supervisord|supervisor|3.2.2|=|| CVE-2017-11610|supervisord|supervisor|3.2.3|=|| CVE-2017-11610|supervisord|supervisor|3.3.0|=|| CVE-2017-11610|supervisord|supervisor|3.3.1|=|| CVE-2017-11610|supervisord|supervisor|3.3.2|=|| CVE-2019-12105|supervisord|supervisor|||4.0.2|<= CVE-2023-27482|home-assistant|supervisor|||2023.03.1|< Set the CVE_PRODUCT explicitly to match relevant CVEs. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 77ba5f3) Signed-off-by: Himanshu Jadon <hjadon@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
https://www.postfix.org/announcements/postfix-3.11.3.html Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
The vulnerability only affects the Go implementation of the library, not the Python one. Ignore this CVE due to this. Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33186 GHSA-p77j-4mvh-x3m3 Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Analysis: - CVE-2024-7246 [4] affects gRPC-C++ CHTTP2 HPACK parser error handling. - The upstream fix from v1.62.3 [1] modifies gRPC core runtime source src/core/ext/transport/chttp2/transport/hpack_parser.cc. aligned with the original fix in v1.60.2 [2] as referenced in [3]. - python3-grpcio-tools does not include or compile this runtime source. - Hence CVE-2024-7246 is not applicable to python3-grpcio-tools. [1] grpc/grpc@1d172cf [2] grpc/grpc@88b1244 [3] https://bugzilla.suse.com/show_bug.cgi?id=1228919 [4] https://nvd.nist.gov/vuln/detail/CVE-2024-7246 Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Analysis: - CVE-2024-11407 [1] affects gRPC-C++ servers with transmit zero copy enabled. - The upstream fix modifies gRPC core runtime source src/core/lib/event_engine/posix_engine/posix_endpoint.cc [2]. - python3-grpcio-tools does not include or compile this runtime source. - Hence CVE-2024-11407 is not applicable to python3-grpcio-tools. [1] https://nvd.nist.gov/vuln/detail/CVE-2024-11407 [2] grpc/grpc@e9046b2 Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This patch applies the upstream fix as referenced in [2], which addresses a Tornado flaw where crafted multipart/form-data requests can trigger excessive synchronous parsing and cause denial of service using the commit shown in [1]. [1] tornadoweb/tornado@119a195 [2] https://security-tracker.debian.org/tracker/CVE-2026-31958 Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-31958 Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
A heap memory buffer overflow might occur in a worker process when using a configuration with overlapping captures in ngx_http_rewrite_module, potentially resulting in arbitrary code execution. The buffer length calculation for static-length rewrite replacements incorrectly used r->uri.data/r->uri.len for escape-size accounting across all captures instead of the actual per-capture offsets into r->captures_data. This allowed overlapping captures to exceed the allocated buffer. Fix by iterating captures using the captures[] offsets into captures_data rather than the full URI string. Upstream-Status: Backport [nginx/nginx@3f135ae] CVE: CVE-2026-9256 Signed-off-by: Nelson Garcia <nelson831002@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Upstream-Status: Backport [strongswan/strongswan@56c7f0d] Signed-off-by: Nitin Wankhade <nitin.wankhade333@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Upstream-Status: Backport [strongswan/strongswan@8dae560] [strongswan/strongswan@4da8401] Signed-off-by: Nitin Wankhade <nitin.wankhade333@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Upstream-Status: Backport [strongswan/strongswan@aa5aaeb] Signed-off-by: Nitin Wankhade <nitin.wankhade333@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Upstream-Status: Backport [strongswan/strongswan@64130ed] [strongswan/strongswan@c66143d] Signed-off-by: Nitin Wankhade <nitin.wankhade333@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Upstream-Status: Backport [strongswan/strongswan@1e0643b] Signed-off-by: Nitin Wankhade <nitin.wankhade333@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Upstream-Status: Backport [strongswan/strongswan@e067d24] Signed-off-by: Nitin Wankhade <nitin.wankhade333@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
The upstream fix [3] is for a newer jq codebase. Debian has already backported this fix in jq 1.8.1-6. Use the Debian patch [1], which fixes this CVE as tracked in Debian bug #1136445 [2]. [1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-40612.patch [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445 [3] jqlang/jq@d1a1256 Reference: GHSA-r7m6-x9c7-h69j Signed-off-by: Shubham Pushpkar <spushpka@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
The upstream fix [3] is for a newer jq codebase. Debian has already backported this fix in jq 1.8.1-6. Use the Debian patch [1], which fixes this CVE as tracked in Debian bug #1136445 [2]. [1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-41256.patch [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445 [3] jqlang/jq@5a015de Reference: GHSA-vf2h-chrj-q3fg Signed-off-by: Shubham Pushpkar <spushpka@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
The upstream fix [3] is for a newer jq codebase. Debian has already backported this fix in jq 1.8.1-6. Use the Debian patch [1], which fixes this CVE as tracked in Debian bug #1136445 [2]. [1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-41257.patch [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445 [3] jqlang/jq@01b3cde Signed-off-by: Shubham Pushpkar <spushpka@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
The upstream fix [3] is for a newer jq codebase. Debian has already backported this fix in jq 1.8.1-7. Use the Debian patch [1], which fixes this CVE as tracked in Debian bug #1136445 [2]. [1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-43894.patch [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445 [3] jqlang/jq@9761ceb Reference: GHSA-5v7p-2r57-2g4g Signed-off-by: Shubham Pushpkar <spushpka@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
The upstream fix [3] is for a newer jq codebase. Debian has already backported this fix in jq 1.8.1-7. Use the Debian patch [1], which fixes this CVE as tracked in Debian bug #1136445 [2]. [1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-43896.patch [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445 [3] jqlang/jq@532ccea Reference: GHSA-mg96-6h3q-g846 Signed-off-by: Shubham Pushpkar <spushpka@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Backport patch [1] mentioned in [2]. [1] nginx/nginx@60c4243 [2] https://security-tracker.debian.org/tracker/CVE-2026-48142 Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com> Reviewed-by: Bruno Vernay <bruno.vernay@se.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
syslog-ng 4.6.0 ships with Config version 4.2, but the configuration files still declare @Version: 3.36. This causes two warnings at startup: WARNING: Configuration file format is too old, syslog-ng is running in compatibility mode WARNING: Your configuration file uses an obsoleted keyword Update the @Version to 4.2 to match the binary's config version. Also replace the deprecated stats_freq() option with the modern stats(freq()) syntax, and add @include "scl.conf" for the systemd config to align with current upstream recommendations. These changes mirror what was done in fee1274 ("syslog-ng: upgrade 4.7.0 -> 4.8.1") for the master branch, adapted for the 4.6.0 version on scarthgap. Signed-off-by: Venkatasainath Ravikanti <venkatasainath.ravikanti@windriver.com> Assisted-by: Kiro:claude-sonnet-4 Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Backport from wrynose (bcc1c15). Adapted from the 1.9.19 -> 1.9.20 upgrade since scarthgap ships 1.9.18. ChangeLog: https://github.com/jirka-h/haveged/releases/tag/v1.9.20 (cherry picked from commit bcc1c15) Signed-off-by: Li Zhou <li.zhou@windriver.com> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com> Signed-off-by: Venkatasainath Ravikanti <venkatasainath.ravikanti@windriver.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com> [scarthgap: adapted for 1.9.18 base recipe] Assisted-by: Kiro (Amazon) Signed-off-by: Venkatasainath Ravikanti <venkatasainath.ravikanti@windriver.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Backport from wrynose (8bd9783). Fixes CVE-2026-41054 (local privilege escalation via command socket credential check bypass). Changelog: =========== * Add ReadWritePaths=/dev/shm to systemd service for semaphore creation under ProtectSystem=full sandboxing * Fix privilege escalation via command socket (CVE-2026-41054) * Check peer credentials before reading command (CVE-2026-41054) * Handle failing opening of semaphore * Fix /dev/shm permissions to use sticky bit * Use chmod after mkdir to ensure correct /dev/shm permissions * Update libtool: add lib64 search paths, remove dead code Tested: Built core-image-full-cmdline for qemux86-64 (scarthgap, bitbake 2.8). Booted in QEMU, verified haveged 1.9.22 starts and provides entropy (entropy_avail=256, pool full). (cherry picked from commit 8bd9783) Signed-off-by: Wang Mingyu <wangmy@fujitsu.com> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com> Signed-off-by: Venkatasainath Ravikanti <venkatasainath.ravikanti@windriver.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com> Assisted-by: Kiro (Amazon) Signed-off-by: Venkatasainath Ravikanti <venkatasainath.ravikanti@windriver.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Changes in oe-core commit a0151ab56cf3 (setuptools3: clean the build directory in configure) cause the build directory to be cleared during configure step. To avoid the downloaded sources from getting cleaned, pre-fetch them to a separate downloads/ directory and patch source to look there. Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Signed-off-by: rfmibuild <NIBuildFarmSupport@ni.com>
usercw88
requested changes
Jul 17, 2026
There was a problem hiding this comment.
@Shreejit-03 This commit is signed by rfmibuild. Can you update the commit message to be signed by yourself
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merge latest from upstream. No conflicts.
Justification
AB#3918183.
Testing
@ni/rtos