Hetvi Thakar
b5874ea07d
libssh: Fix CVE-2026-59850
...
The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59850 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=6edfb52b3b364577d2db0334c0514a977efceed2
[2] https://www.libssh.org/security/advisories/CVE-2026-59850.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-02 10:39:59 +05:30
Hetvi Thakar
6e303a0123
libssh: Fix CVE-2026-59848
...
The stable-0.11 commit shown in [1] is the primary upstream fix selected
for this backport. Commit [2] corrects the request-queue pointer state
introduced by [1], so it is carried immediately afterward as a regression
fix. The upstream advisory [3] documents CVE-2026-59848 and identifies
libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=a30a51003205744c10ba4439306f555206ae8497
[2] https://git.libssh.org/projects/libssh.git/commit/?id=5309aefd99e1775db40bf20869f1fb1cc6c787be
[3] https://www.libssh.org/security/advisories/CVE-2026-59848.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-02 10:39:59 +05:30
Hetvi Thakar
df16e6650d
libssh: Fix CVE-2026-59846
...
libssh 0.10.6 predates the username-validation helper used by the
stable-0.11 fix, so the upstream commit in [1] cannot be applied as-is.
Adapt the same dangerous-character check directly at the ProxyCommand %r
expansion sink and add focused regression coverage.
The upstream advisory [2] identifies libssh 0.11.5 and 0.12.1 as the
fixed releases.
[1] https://gitlab.com/libssh/libssh-mirror/-/commit/56ce3c193eb06af5bf3b07ec0b4c7308b5c72130
[2] https://www.libssh.org/security/advisories/CVE-2026-59846.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-02 10:39:58 +05:30
Hetvi Thakar
0428dc2fe2
libssh: Fix CVE-2026-59844
...
The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59844 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9
[2] https://www.libssh.org/security/advisories/CVE-2026-59844.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-02 10:39:24 +05:30
Hetvi Thakar
f6b642b915
libssh: Fix CVE-2026-59843
...
The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59843 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919
[2] https://www.libssh.org/security/advisories/CVE-2026-59843.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-02 10:38:54 +05:30
Hitendra Prajapati
8a6e67f063
opensc: fix for CVE-2026-40528
...
Pick patch from [1] also mentioned at NVD report in [2]
[1] https://github.com/OpenSC/OpenSC/commit/0358817ec74aeca654f83e7709c7720b14c5db59
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-40528
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-01 10:17:58 +05:30
Gyorgy Sarvari
216e1b3a2e
smarty: extend CVE_PRODUCT
...
Some CVEs assign smarty-php as the vendor to the corresponding CPE.
E.g CVE-2024-35226[1] is tracked with smarty-php:smarty by mitre
(NVD tracks it without CPE).
[1]: https://cveawg.mitre.org/api/cve/CVE-2024-35226
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com >
Signed-off-by: Khem Raj <raj.khem@gmail.com >
(cherry picked from commit 1aee6a403c )
Signed-off-by: Devansh Patel <devanshp@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-01 06:57:24 +05:30
Benjamin Bouvier
7b773a2854
rsyslog: add CVE_PRODUCT
...
Add exact CPE name in CVE_PRODUCT.
Signed-off-by: Benjamin Bouvier <benjamin.bouvier@ekinops.com >
Signed-off-by: Khem Raj <raj.khem@gmail.com >
(cherry picked from commit 42761ba945 )
Signed-off-by: Devansh Patel <devanshp@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-01 06:57:24 +05:30
Vijay Anusuri
2e49cdb4d2
giflib: Fix CVE-2026-26740
...
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-26740
[2] https://ubuntu.com/security/CVE-2026-26740
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-01 06:57:07 +05:30
Ankur Tyagi
6bb11ad0c3
jsoncpp: upgrade 1.9.5 -> 1.9.7
...
https://github.com/open-source-parsers/jsoncpp/releases/tag/1.9.6
https://github.com/open-source-parsers/jsoncpp/releases/tag/1.9.7
Also backport patch to fix C++11 ABI breakage when compiled with C++17.
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-01 06:57:06 +05:30
Devansh Patel
6bfefb82b3
hdf5: Fix CVE-2026-26197
...
This patch backports the upstream fix first released in HDF5 2.1.0.
The upstream fix commit is referenced in [1], and the public advisory
is referenced in [2].
Although the advisory [2] lists HDF5 2.0.0 as affected, NVD [3]
also marks versions before 2.0.0 as affected, and its CPE
configuration marks versions before 2.1.0 as vulnerable. Scarthgap's
HDF5 1.14.4-3 H5T_ARRAY decoder in src/H5Odtype.c computes the array
element count and decodes the parent datatype without checking for
multiplication overflow or verifying that the stored datatype size
matches the element size multiplied by the element count. The
vulnerable code path is therefore present in 1.14.4-3, so this
backport is applicable.
[1] https://github.com/HDFGroup/hdf5/commit/8cd9f7a7ba6757fbb72e36bbe23e127f8507c8a6
[2] https://github.com/HDFGroup/hdf5/security/advisories/GHSA-gh44-7wpq-622f
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-26197
Signed-off-by: Devansh Patel <devanshp@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-01 06:57:06 +05:30
Devansh Patel
436a33ff4c
hdf5: Fix CVE-2026-26199
...
This patch backports the upstream fix first released in HDF5 2.1.0.
The upstream fix commit is referenced in [1], and the public advisory
is referenced in [2].
[1] https://github.com/HDFGroup/hdf5/commit/9268b803b742f99c1f8793cae74f19e74976b065
[2] https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5c6x-jmgf-f5vc
Signed-off-by: Devansh Patel <devanshp@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-01 06:57:05 +05:30
Hitendra Prajapati
9e103dc4d0
libssh: fix for CVE-2026-59845, CVE-2026-59847
...
Pick patch from [1], [2] & [3] also mentioned at Debian report in [4] & [5]
[1] https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f
[2] https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074
[3] https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9
[4] https://security-tracker.debian.org/tracker/CVE-2026-59845
[5] https://security-tracker.debian.org/tracker/CVE-2026-59847
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-01 06:57:05 +05:30
Hitendra Prajapati
085604ac0b
libssh: set status for CVE-2026-59842
...
Analysis:
- CVE-2026-59842 affects information disclosure via short GSSAPI Curve25519 public key.
- This vulnerable code is not present in the current libssh 0.10.6.
- Hence ignoring the CVE for this version.
Reference:
1. https://www.cve.org/CVERecord?id=CVE-2026-59842
2. https://www.libssh.org/security/advisories/CVE-2026-59842.txt
3. https://security-tracker.debian.org/tracker/CVE-2026-59842
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-01 06:57:04 +05:30
Hitendra Prajapati
b8bc579daa
libssh: set status for CVE-2026-15370
...
Analysis:
- CVE-2026-15370 affects stack buffer overflow in SFTP server longname construction.
- This vulnerable code is not present in the current libssh 0.10.6.
- Hence ignoring the CVE for this version.
Reference:
https://www.cve.org/CVERecord?id=CVE-2026-15370
https://www.libssh.org/security/advisories/CVE-2026-15370.txt
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-09-01 06:57:04 +05:30
Adarsh Jagadish Kamini
bec755063a
thrift: fix CVE-2026-58389
...
Backport patch to fix CVE-2026-58389.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-58389
Upstream fix:
https://github.com/apache/thrift/commit/0ab16e3a83637711f4e0f788c205f66576fd0a55
Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-13 10:01:51 +05:30
Roland Kovacs
356ce58534
thrift: fix multiple CVEs
...
CVE-2026-43868:
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.
CVE-2026-43869:
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This CVE only affects the Java client, which is not built by the recipe. Marked as
'not-applicable-config'.
Upstream commit:
https://github.com/apache/thrift/commit/a30c552bd0808b7e19f35ad30212ba7a9aee8c66
CVE-2026-43870:
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers
('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability
in Apache Thrift.
Signed-off-by: Roland Kovacs <roland.kovacs@est.tech >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-13 10:01:51 +05:30
Tugrul Kukul
6e099da67d
jq: fix CVE-2026-44777
...
Backport patch to fix CVE-2026-44777.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-44777
Upstream fix:
https://github.com/jqlang/jq/commit/f58787c41835d9b17795730cb04925fdba25c71c
Tested with ptest:
Before: PASSED: 7, FAILED: 0, SKIPPED: 0
After: PASSED: 7, FAILED: 0, SKIPPED: 0
Signed-off-by: Tugrul Kukul <tugrul.kukul@est.tech >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-13 10:01:51 +05:30
Tugrul Kukul
65604c0d46
jq: fix CVE-2026-39956
...
Backport patch to fix CVE-2026-39956.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-39956
https://www.cve.org/CVERecord?id=CVE-2026-39956
https://security-tracker.debian.org/tracker/CVE-2026-39956
https://osv.dev/list?q=CVE-2026-39956
Upstream fix:
https://github.com/jqlang/jq/commit/fdf8ef0f0810e3d365cdd5160de43db46f57ed03 [nvd]
Tested with ptest:
Before: PASSED: 7, FAILED: 0, SKIPPED: 0
After: PASSED: 7, FAILED: 0, SKIPPED: 0
Signed-off-by: Tugrul Kukul <tugrul.kukul@est.tech >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-13 10:01:51 +05:30
Ankur Tyagi
265199312c
redis: upgrade 6.2.21 -> 6.2.23
...
https://github.com/redis/redis/releases/tag/6.2.22
https://github.com/redis/redis/releases/tag/6.2.23
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-12 09:35:14 +05:30
Ankur Tyagi
1bc6d30b77
redis: upgrade 7.2.12 -> 7.2.15
...
Refreshed patches for this version.
https://github.com/redis/redis/releases/tag/7.2.13
https://github.com/redis/redis/releases/tag/7.2.14
https://github.com/redis/redis/releases/tag/7.2.15
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-12 09:35:13 +05:30
Vijay Anusuri
319421fd5b
libssh: Remove duplicate CVE_STATUS entry for CVE-2025-14821
...
The CVE_STATUS entry for CVE-2025-14821 was added twice in the recipe.
Remove the duplicate entry to keep the recipe clean
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-12 09:35:13 +05:30
Emanuele Ghidoli
07d8247914
jq: fix build broken by the CVE-2026-43895 backport
...
Since da15df26e6 ("jq: Fix CVE-2026-43895") "bitbake jq" fails with:
cc1: fatal error: src/parser.c: No such file or directory
That patch is the only jq patch touching both src/parser.c and
src/parser.y. git orders the diff alphabetically, so patch(1) writes
parser.y after parser.c and the shipped pre-generated parser looks
outdated. Maintainer mode is disabled, so make runs the no-op '.y.c'
rule; having "rebuilt" the target it stops resolving it through VPATH and
looks for it in ${B}, where it does not exist.
Touch the generated bison/flex sources before configure so they are never
considered stale. This also covers any future patch touching src/parser.y
or src/lexer.l.
With maintainer mode enabled bison will no longer regenerate parser.c,
which is fine: the CVE patches update the .y and the generated .c
consistently.
Signed-off-by: Emanuele Ghidoli <emanuele.ghidoli@toradex.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-12 09:35:04 +05:30
Benjamin Bouvier
3a32c083e1
librelp: add CVE_PRODUCT
...
Add exact CPE name in CVE_PRODUCT.
Signed-off-by: Benjamin Bouvier <benjamin.bouvier@ekinops.com >
Signed-off-by: Khem Raj <raj.khem@gmail.com >
(cherry picked from commit 09c542c2f4 )
Signed-off-by: Devansh Patel <devanshp@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-12 09:35:03 +05:30
Adarsh Jagadish Kamini
35cb02fda2
thrift: fix CVE-2026-48144
...
Backport patch to fix CVE-2026-48144.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-48144
Upstream fix:
https://github.com/apache/thrift/commit/2b8baabc9be52807b08825e825bc0cd26568a193
Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-12 09:35:02 +05:30
Adarsh Jagadish Kamini
7f5c686d97
thrift: fix CVE-2026-58023
...
Backport patch to fix CVE-2026-58023.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-58023
Upstream fix:
https://github.com/apache/thrift/commit/d68305a7308a11df2c1daef16f55dbc19dfa6ff0
Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-12 09:35:01 +05:30
Adarsh Jagadish Kamini
c83d3fa4c2
thrift: fix CVE-2026-55971
...
Backport patch to fix CVE-2026-55971.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-55971
Upstream fix:
https://github.com/apache/thrift/commit/db4a473f3a984eee27273256fe737be5dd175595
Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-12 09:35:01 +05:30
Jason Schonberg
7e6a93e1ce
php: upgrade 8.2.32 -> 8.2.33
...
This is a security release.
Changelog: https://www.php.net/ChangeLog-8.php#8.2.33
Signed-off-by: Jason Schonberg <schonm@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-12 09:34:58 +05:30
Hetvi Thakar
ef3df29f2c
libdbi-perl: Fix CVE-2026-14740
...
This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].
[1] https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-14740
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-30 07:53:25 +05:30
Hetvi Thakar
3dd0a40ecb
libdbi-perl: Fix CVE-2026-14739
...
Backport the upstream hard limit for positional placeholders. This is
a follow-up to CVE-2026-10879 and depends on the allocation fix from
the preceding libdbi-perl commit.
Correct the upstream boundary check so that the documented maximum of
99999 placeholders is accepted and values above it are rejected. Add
focused regression coverage for the 99999 and 100000 boundaries.
[1] https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395
[2] https://github.com/perl5-dbi/dbi/commit/af79036c07aa9a457971c0f4136e37c85dc20978
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-14739
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-10879
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-30 07:53:25 +05:30
Hetvi Thakar
dacd50f84e
libdbi-perl: Fix CVE-2026-14380
...
Backport the ordered upstream fix and regression-test chain from DBI
1.650. Add perl-module-load to RDEPENDS to satisfy the runtime
dependency introduced by the primary fix's use of Module::Load.
[1] https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259
[2] https://github.com/perl5-dbi/dbi/commit/d982411aec73b3acfc4e9e465358bca9eb7fede8
[3] https://github.com/perl5-dbi/dbi/commit/f94685f415b08ea4b1f183d48430c4583c1c07d0
[4] https://github.com/perl5-dbi/dbi/commit/7949e551b3c7a8854926b6de84f6cc2ceafb2200
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-14380
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-30 07:53:25 +05:30
Hetvi Thakar
3304a04085
libdbi-perl: Fix CVE-2026-10879
...
This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].
[1] https://github.com/perl5-dbi/dbi/commit/af79036c07aa9a457971c0f4136e37c85dc20978
[2] https://security-tracker.debian.org/tracker/CVE-2026-10879
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-30 07:53:25 +05:30
Hetvi Thakar
ba75c3486c
libdbi-perl: Fix CVE-2026-9698
...
This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].
[1] https://github.com/perl5-dbi/dbi/commit/bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-9698
Signed-off-by: Hetvi Thakar <hthakar@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-30 07:53:25 +05:30
Qliangw
6fe53daabc
libuio: fix FILE descriptor leak
...
The function uio_line_from_file() fails to close the FILE pointer
when fgets() returns NULL, causing a file descriptor leak.
This can be triggered when reading from /sys files that return
empty content, leading to resource exhaustion over time.
Fix this by using goto-based error handling to ensure fclose()
is called on all exit paths.
Signed-off-by: Qliangw <qili00001@gmail.com >
(cherry picked from commit cd75edf25d )
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
(cherry picked from commit d97b5602d7 )
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-29 09:45:00 +05:30
Wang Mingyu
f056a64405
monocypher: upgrade 4.0.2 -> 4.0.3
...
Changelog:
===========
- Fixed timing leak vulnerability in EdDSA/Ed25519 signatures.
- Various minor documentation fixes.
- Various minor build system fixes.
- Various minor compiler warning fixes.
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 25cfd0324c )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-29 08:44:27 +05:30
Ankur Tyagi
925aadf07c
haveged: upgrade 1.9.22 -> 1.9.23
...
Release Notes:
https://github.com/jirka-h/haveged/releases/tag/v1.9.23
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-29 08:44:21 +05:30
Darsh Kelaiya
ce23e14868
jq: Fix CVE-2026-54679
...
This patch applies the upstream fix for CVE-2026-54679 as referenced
in [2], using the upstream commit identified in [1].
[1] https://github.com/jqlang/jq/commit/46d1da30944ce93dd671ac72b6513fc0eb747837
[2] https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-29 08:44:08 +05:30
Darsh Kelaiya
6d3530d6a1
jq: Fix CVE-2026-49839
...
This patch applies the upstream fix as referenced in [2], using the commit shown in [1].
[1] https://github.com/jqlang/jq/commit/e987df0d463d85fd70825e042a082427e8275b86
[2] https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-29 08:44:08 +05:30
Darsh Kelaiya
624fedbfa0
jq: Fix CVE-2026-47770
...
This patch applies the upstream fix for CVE-2026-47770 as referenced
in [2], using the upstream commit identified in [1].
[1] https://github.com/jqlang/jq/commit/7122866869960b55cea3646bc91334ef55787831
[2] https://github.com/jqlang/jq/security/advisories/GHSA-3pgx-frr7-3jxp
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-29 08:44:07 +05:30
Darsh Kelaiya
da15df26e6
jq: Fix CVE-2026-43895
...
This patch applies the upstream fix as referenced in [2], using the commit shown in [1].
[1] https://github.com/jqlang/jq/commit/9d223f153c3632a207fa071caaa6292da33ae361
[2] https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-29 08:44:07 +05:30
Peter Marko
2bc33d99c9
hostapd: set status for CVE-2026-58374
...
As desctibed in [1], vulnerable code is not yet present in 2.10.
[1] https://security-tracker.debian.org/tracker/CVE-2026-58374
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-29 08:44:06 +05:30
Deepak Rathore
8b23408f0d
ldns: fix CVE-2026-10846
...
This patch backports the upstream fixes released in ldns 1.9.2 for
CVE-2026-10846.The upstream commits are referenced in [1], [2], and
[3], and the public CVE advisory is referenced in [4].The individual
backported commit links are also recorded in the embedded patch headers.
[1] https://github.com/NLnetLabs/ldns/commit/a21fb16686bbe3355886905f95e13eab5144d805
[2] https://github.com/NLnetLabs/ldns/commit/9ea51a68d458b43a17ccf4ee98a71325300df524
[3] https://github.com/NLnetLabs/ldns/commit/dc117528dfc60b2dda82d9171b7e9e0b6890da2f
[4] https://www.nlnetlabs.nl/downloads/ldns/CVE-2026-10846.txt
Signed-off-by: Deepak Rathore <deeratho@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-29 08:44:05 +05:30
Peter Marko
2b04d2036c
libwebsockets: patch CVE-2026-10650
...
Pick patch mentioned in NVD report.
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-29 08:44:05 +05:30
Deepak Rathore
e802c281bf
libidn: fix CVE-2026-57053
...
This patch applies the upstream v1.44 backport for
CVE-2026-57053. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://git.savannah.gnu.org/cgit/libidn.git/commit/?id=f57fab06afc1e328bbe197ad3d4a4e83c829593e
[2] https://www.cve.org/CVERecord?id=CVE-2026-57053
Signed-off-by: Deepak Rathore <deeratho@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-16 15:49:43 +05:30
Deepak Rathore
b02e2e66cb
nmap: fix CVE-2026-58058
...
This patch applies the upstream master backport for
CVE-2026-58058. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83
[2] https://github.com/advisories/GHSA-wxvj-hc4r-fq45
Signed-off-by: Deepak Rathore <deeratho@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-16 15:49:43 +05:30
Yunseong Kim
c8dc986a39
libyang: Fix CVE-2026-41401 and CVE-2026-44673
...
CVE-2026-41401:
Fix incorrect metadata list pointer update in lyd_parse_set_data_flags()
when freeing the head metadata entry. Without this fix, crafted YANG XML
documents with specific metadata ordering can trigger invalid pointer
states in the metadata linked list.
CVE-2026-44673:
Fix integer overflow and OOM in the LYB binary parser. lyb_read_string()
wraps len + 1 to 0 when len == UINT64_MAX, and lyb_read_term_value()
truncates uint64_t to uint32_t causing undersized allocation. Both paths
are reachable via malformed LYB input with crafted length fields.
Signed-off-by: Yunseong Kim <yunseong.kim@est.tech >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-16 15:49:42 +05:30
Esa Jaaskela
1f99172329
uutils-coreutils: fix buildpaths QA warning
...
The onig_sys and blake3 crates build bundled C via cc crate. The build
path leaks into the the -dbg binary and trips the buildpaths QA check.
Add a -fdebug-prefix-map for ${CARGO_HOME} to CFLAGS to add a correct
mapping.
Signed-off-by: Esa Jaaskela <esa.jaaskela@suomi24.fi >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-16 15:49:41 +05:30
Etienne Cordonnier
f7fbf8f078
uutils-coreutils: disable stdbuf compilation
...
There is a bug in uutils-coreutils causing stdbuf to include the HOST version of libstdbuf.so, even when cross-compiled.
As a side-effect, the uutils-coreutils binary was containing the buildpath, because RPATH was set on libstdbuf.so.
Thus the buildpath error can be re-enabled.
This is tracked upstream by https://github.com/uutils/coreutils/issues/6591
Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com >
Co-authored-by: Gyorgy Sarvari <skandigraun@gmail.com >
Signed-off-by: Khem Raj <raj.khem@gmail.com >
(cherry picked from commit 1d43511321 )
Signed-off-by: Esa Jaaskela <esa.jaaskela@suomi24.fi >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-16 15:49:41 +05:30
Jason Schonberg
66bd2e6b6d
php: upgrade 8.2.31 -> 8.2.32
...
This is a security release.
Changelog: https://www.php.net/ChangeLog-8.php#8.2.32
Signed-off-by: Jason Schonberg <schonm@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-16 15:49:39 +05:30
Sudhir Dumbhare
6dfa3a26e3
mariadb: upgrade 10.11.16 -> 10.11.18
...
This upgrades the 10.11 LTS recipe to the upstream release containing fixes for:
- CVE-2026-44168
- CVE-2026-44170
- CVE-2026-44171
- CVE-2026-44173
- CVE-2026-48163
- CVE-2026-48165
- CVE-2026-49261
Release notes:
- https://mariadb.com/docs/release-notes/community-server/10.11/10.11.18
- https://mariadb.com/docs/release-notes/community-server/10.11/10.11.17
Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-16 15:49:38 +05:30