[prev in list] [next in list] [prev in thread] [next in thread]
List: openembedded-core
Subject: [OE-core][dunfell 00/13] Patch review
From: "Steve Sakoman" <steve () sakoman ! com>
Date: 2023-09-30 19:39:57
Message-ID: cover.1696102675.git.steve () sakoman ! com
[Download RAW message or body]
Content-Transfer-Encoding: 8bit
Please review this set of changes for dunfell and have comments back by
end of day Tuesday, October 3
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/typhoon/#/builders/83/builds/5966
The following changes since commit a9d194f21a3bdebca8aaff204804a5fdc67c76d1:
vim: Upgrade 9.0.1664 -> 9.0.1894 (2023-09-25 07:03:13 -1000)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/dunfell-nut
http://cgit.openembedded.org/openembedded-core-contrib/log/?h=stable/dunfell-nut
Alexander Kanavin (1):
nasm: update 2.15.03 -> 2.15.05
Archana Polampalli (1):
nasm: fix CVE-2022-44370
Ashish Sharma (1):
mdadm: Backport fix for CVE-2023-28736
Bruce Ashfield (4):
linux-yocto/5.4: update to v5.4.252
linux-yocto/5.4: update to v5.4.254
linux-yocto/5.4: update to v5.4.256
linux-yocto/5.4: update to v5.4.257
Colin McAllister (1):
libwebp: Fix CVE-2023-5129
Lee Chee Yang (3):
libxpm: fix CVE-2022-46285
qemu: fix CVE-2020-24165
python3: update to 3.8.18
Siddharth Doshi (1):
go: Fix CVE-2023-39318 and CVE-2023-39319
Vijay Anusuri (1):
ghostscript: fix CVE-2023-36664
meta/recipes-devtools/go/go-1.14.inc | 2 +
.../go/go-1.14/CVE-2023-39318.patch | 238 ++++++++++++
.../go/go-1.14/CVE-2023-39319.patch | 230 +++++++++++
.../0002-Add-debug-prefix-map-option.patch | 42 +-
.../nasm/nasm/CVE-2022-44370.patch | 104 +++++
.../nasm/{nasm_2.15.03.bb => nasm_2.15.05.bb} | 5 +-
.../{python3_3.8.17.bb => python3_3.8.18.bb} | 4 +-
meta/recipes-devtools/qemu/qemu.inc | 1 +
.../qemu/qemu/CVE-2020-24165.patch | 94 +++++
.../ghostscript/CVE-2023-36664-1.patch | 145 +++++++
.../ghostscript/CVE-2023-36664-2.patch | 60 +++
.../ghostscript/CVE-2023-36664-pre1.patch | 62 +++
.../ghostscript/ghostscript_9.52.bb | 3 +
.../mdadm/files/CVE-2023-28736.patch | 77 ++++
meta/recipes-extended/mdadm/mdadm_4.1.bb | 1 +
.../xorg-lib/libxpm/CVE-2022-46285.patch | 40 ++
.../xorg-lib/libxpm_3.5.13.bb | 2 +
.../linux/linux-yocto-rt_5.4.bb | 6 +-
.../linux/linux-yocto-tiny_5.4.bb | 8 +-
meta/recipes-kernel/linux/linux-yocto_5.4.bb | 22 +-
.../webp/files/CVE-2023-5129.patch | 364 ++++++++++++++++++
meta/recipes-multimedia/webp/libwebp_1.1.0.bb | 1 +
22 files changed, 1467 insertions(+), 44 deletions(-)
create mode 100644 meta/recipes-devtools/go/go-1.14/CVE-2023-39318.patch
create mode 100644 meta/recipes-devtools/go/go-1.14/CVE-2023-39319.patch
create mode 100644 meta/recipes-devtools/nasm/nasm/CVE-2022-44370.patch
rename meta/recipes-devtools/nasm/{nasm_2.15.03.bb => nasm_2.15.05.bb} (80%)
rename meta/recipes-devtools/python/{python3_3.8.17.bb => python3_3.8.18.bb} (99%)
create mode 100644 meta/recipes-devtools/qemu/qemu/CVE-2020-24165.patch
create mode 100644 meta/recipes-extended/ghostscript/ghostscript/CVE-2023-36664-1.patch
create mode 100644 meta/recipes-extended/ghostscript/ghostscript/CVE-2023-36664-2.patch
create mode 100644 meta/recipes-extended/ghostscript/ghostscript/CVE-2023-36664-pre1.patch
create mode 100644 meta/recipes-extended/mdadm/files/CVE-2023-28736.patch
create mode 100644 meta/recipes-graphics/xorg-lib/libxpm/CVE-2022-46285.patch
create mode 100644 meta/recipes-multimedia/webp/files/CVE-2023-5129.patch
--
2.34.1
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#188465): https://lists.openembedded.org/g/openembedded-core/message/188465
Mute This Topic: https://lists.openembedded.org/mt/101681322/4454766
Group Owner: openembedded-core+owner@lists.openembedded.org
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [openembedded-core@marc.info]
-=-=-=-=-=-=-=-=-=-=-=-
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic