Commit Graph
38418 Commits
Author SHA1 Message Date
Ankur Tyagi bb1a4701e6 libheif: patch CVE-2026-32741
Backport commit identified by Debian[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32741

[1]https://security-tracker.debian.org/tracker/CVE-2026-32741

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:08 +05:30
Ankur Tyagi f179d08aed libheif: patch CVE-2026-32740
Backport commit identified by Debian[1] to the original file which was
renamed by upstream commit[2].

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32740

[1]https://security-tracker.debian.org/tracker/CVE-2026-32740
[2]https://github.com/strukturag/libheif/commit/f05c61ee8427ac3e39a3e5802a390b5aa99ae281

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:08 +05:30
Ankur Tyagi 6bc5abde11 libheif: patch CVE-2026-32739
Backport commit identified by Debian[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32739

[1]https://security-tracker.debian.org/tracker/CVE-2026-32739

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:07 +05:30
Ankur Tyagi 18e20ab7d2 libheif: patch CVE-2026-32738
Backport commit identified by Debian[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32738

[1]https://security-tracker.debian.org/tracker/CVE-2026-32738

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:07 +05:30
Ankur Tyagi 635e8fd545 libfido2, libfido2-initial: ignore CVE-2026-40947
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-40947

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:06 +05:30
Ankur Tyagi 4a63a2afa1 libde265: patch CVE-2026-49346
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-49346

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:06 +05:30
Ankur Tyagi c83399f83f libde265: patch CVE-2026-49337
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-49337

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:06 +05:30
Ankur Tyagi bd09bb41b4 libde265: patch CVE-2026-49295
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-49295

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:05 +05:30
Ankur Tyagi 53bb41bcf0 libde265: mark CVE-2026-45382 and CVE-2026-45383 patched
Release Note[1] also mentions fixed CVE.

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-45382
https://nvd.nist.gov/vuln/detail/cve-2026-45383

[1] https://github.com/strukturag/libde265/releases/tag/v1.0.19

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:05 +05:30
Ankur Tyagi 4a1281dd55 lcms: patch CVE-2026-42798
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-42798

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:04 +05:30
Ankur Tyagi 5060c9fe3a jq: ignore CVE-2025-49014
Details:
https://nvd.nist.gov/vuln/detail/cve-2025-49014

Fixes:
WARNING: jq-1.8.1-r0 do_sbom_cve_check_recipe: jq-1.8.1: Found unpatched CVEs: CVE-2025-49014

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:04 +05:30
Joel Winarske aa32734876 capnproto: build position independent code
The recipe produces static archives only, and does not compile them PIC, so
linking capnp or kj into a shared library fails:

  libkj.a(exception.c++.o): relocation R_X86_64_TPOFF32 against
  `kj::(anonymous namespace)::threadLocalCallback' can not be used when making
  a shared object; local-exec is incompatible with -shared

kj/exception.c++ has a file-scope thread_local, which non-PIC code compiles to
the local-exec TLS model. A shared object cannot use that model, so the link
fails on any consumer that puts capnp inside a .so. Debian and Fedora do not
hit this because they ship shared libcapnp.

Set CMAKE_POSITION_INDEPENDENT_CODE. Packaging is unchanged: still static,
still no .so, no new packages and no ABI surface, only the code model differs.

Backport of the same change sent for master, where the recipe is 1.5.0.

Signed-off-by: Joel Winarske <joel.winarske@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:03 +05:30
Ankur Tyagi 86fba2b580 iniparser: mark CVE-2025-0633 pached
Also mentioned in the release notes[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2025-0633

[1] https://gitlab.com/iniparser/iniparser/-/releases/v4.2.6

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:03 +05:30
Ankur Tyagi 3513e3868e iftop: ignore CVE-2026-3824, CVE-2026-3825 and CVE-2026-3826
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-3824
https://nvd.nist.gov/vuln/detail/cve-2026-3825
https://nvd.nist.gov/vuln/detail/cve-2026-3826

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:02 +05:30
Ankur Tyagi df3f814ab8 hdf5: patch CVE-2026-19025
Backport patch from the PR[1] fixing the issue[2] mentioned in the NVD[3].

[1] https://github.com/HDFGroup/hdf5/pull/6508
[2] https://github.com/HDFGroup/hdf5/issues/6491
[3] https://nvd.nist.gov/vuln/detail/cve-2026-19025

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:02 +05:30
Ankur Tyagi 637f437de9 hdf5: patch CVE-2026-17574
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-17574

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:01 +05:30
Ankur Tyagi f46990293c hdf5: patch CVE-2026-17573
Backport patch from the PR[1] fixing the issue[2] mentioned in the NVD[3].
Debian[4] has also identified the commit.

[1] https://github.com/HDFGroup/hdf5/pull/6160
[2] https://github.com/HDFGroup/hdf5/issues/6124
[3] https://nvd.nist.gov/vuln/detail/cve-2026-17573
[4] https://security-tracker.debian.org/tracker/CVE-2026-17573

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:01 +05:30
Ankur Tyagi c279e9e688 hdf5: patch CVE-2026-17572
Backport patch from the PR[1] fixing the issue[2] mentioned in the NVD[3].
Debian[4] has also identified the commit.

[1] https://github.com/HDFGroup/hdf5/pull/6499
[2] https://github.com/HDFGroup/hdf5/issues/6501
[3] https://nvd.nist.gov/vuln/detail/cve-2026-17572
[4] https://security-tracker.debian.org/tracker/CVE-2026-17572

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:00 +05:30
Ankur Tyagi f1a7be5e8d hostapd: patch CVE-2026-58374
Apply hostapd patches recommended by upstream[1] as mentioned in the NVD[2]

[1] https://w1.fi/security/2026-1/
[2] https://nvd.nist.gov/vuln/detail/cve-2026-58374

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:00 +05:30
Ankur Tyagi 369d962967 gerbera: ignore CVE-2025-23386
Details:
https://nvd.nist.gov/vuln/detail/cve-2025-23386

This vulnerability is due to openSUSE specific packaging issue.

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:52:00 +05:30
Ankur Tyagi 57e1f7d3d2 gpsd: patch CVE-2026-58459
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-58459

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:59 +05:30
Ankur Tyagi e134adc8f3 gpm: ignore CVE-2025-4558
Details:
https://nvd.nist.gov/vuln/detail/cve-2025-4558

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:59 +05:30
Ankur Tyagi 086a780db0 haveged: ignore CVE-2026-41054
Debian[1] also confirms the fixed version.

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-41054

[1] https://security-tracker.debian.org/tracker/CVE-2026-41054

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:58 +05:30
Ankur Tyagi 7dcff13591 freeipmi: patch CVE-2026-50031
Backport patches fixing bugs[1][2] associated with the CVE.

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-50031

[1] https://savannah.gnu.org/bugs/index.php?68363
[2] https://savannah.gnu.org/bugs/index.php?68364

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:58 +05:30
Ankur Tyagi 34d752b5d7 firewalld: patch CVE-2026-4948
Backport commit[1] identified by Debian as a fix.

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-4948

[1] https://security-tracker.debian.org/tracker/CVE-2026-4948

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:57 +05:30
Ankur Tyagi e6d111c169 eject: ignore CVE-2026-28065
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-28065

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:57 +05:30
Ankur Tyagi db080436aa civetweb: ignore CVE-2026-5789
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-5789

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:56 +05:30
Ankur Tyagi 413d02b30e editorconfig-core-c: patch CVE-2026-40489
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-40489

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:56 +05:30
Ankur Tyagi 5910f812d1 editorconfig-core-c: ignore CVE-2024-53849
PR[1] mentioned in the NVD[2] is already part of the upstream version.

[1] https://github.com/editorconfig/editorconfig-core-c/pull/103
[2] https://nvd.nist.gov/vuln/detail/cve-2024-53849

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:55 +05:30
Ankur Tyagi 86a9ad852a dovecot: ignore already fixed CVEs
Upstream has confirmed that these vulnerabilities are fixed,
and Debian has also identified the relevant commits:

CVE-2025-59028: https://security-tracker.debian.org/tracker/CVE-2025-59028
CVE-2025-59032: https://security-tracker.debian.org/tracker/CVE-2025-59032
CVE-2026-27859: https://security-tracker.debian.org/tracker/CVE-2026-27859
CVE-2026-27851: https://security-tracker.debian.org/tracker/CVE-2026-27851
CVE-2026-33603: https://security-tracker.debian.org/tracker/CVE-2026-33603
CVE-2026-40016: https://security-tracker.debian.org/tracker/CVE-2026-40016
CVE-2026-40020: https://security-tracker.debian.org/tracker/CVE-2026-40020
CVE-2026-42006: https://security-tracker.debian.org/tracker/CVE-2026-42006

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:55 +05:30
Ankur Tyagi 53bbf2771b dool: patch CVE-2026-56652
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-56652

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:54 +05:30
Ankur Tyagi 2e1445decd dool: patch CVE-2026-56651
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-56651

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:54 +05:30
Ankur Tyagi cb309d1197 cockpit: mark CVE-2024-2947 patched
commit[1] fixing the CVE is part of the upstream version.

Details:
https://nvd.nist.gov/vuln/detail/cve-2024-2947

Fixes:
WARNING: cockpit-352-r0 do_sbom_cve_check_recipe: cockpit-352: Found unpatched CVEs: CVE-2024-2947

[1] https://github.com/cockpit-project/cockpit/commit/9c4cc9b6df632082538b53bdc8ee9ec1c5cad4da

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:53 +05:30
Ankur Tyagi dcdea72daf bcc: mark CVE-2024-2314 patched
Details:
https://nvd.nist.gov/vuln/detail/cve-2024-2314

Fixes:
WARNING: bcc-0.36.1-r0 do_sbom_cve_check_recipe: bcc-0.36.1: Found unpatched CVEs: CVE-2024-2314

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:53 +05:30
Ankur Tyagi 319e05d92a bubblewrap: mark CVE-2026-41163 patched
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-41163

Fixes:
WARNING: bubblewrap-0.11.2-r0 do_sbom_cve_check_recipe: bubblewrap-0.11.2: Found unpatched CVEs: CVE-2026-41163

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:53 +05:30
Ankur Tyagi 7a26befb15 capnproto: ignore CVE-2026-59704
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-59704

Fixes:
WARNING: capnproto-1.4.0-r0 do_sbom_cve_check_recipe: capnproto-1.4.0: Found unpatched CVEs: CVE-2026-59704

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:52 +05:30
Ankur Tyagi 3d4c0a43e7 proftpd: upgrade 1.3.9c -> 1.3.9d
Changelog:
https://github.com/proftpd/proftpd/blob/v1.3.9d/NEWS

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit f4b73e8ec1)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:52 +05:30
Jason Schonberg 9a79c379b9 php: upgrade 8.5.9 -> 8.5.10
This is a bug fix release.

Changelog: https://www.php.net/ChangeLog-8.php#8.5.10

Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit e5f8c8d53a)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:51 +05:30
Ankur Tyagi 581dced0d0 asyncmqtt: upgrade 10.3.0 -> 10.3.1
Changelog:
https://github.com/redboltz/async_mqtt/releases/tag/10.3.1

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 965ab7088d)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:51 +05:30
Abhishek Bachiphale a962aa88d3 thrift: fix CVE-2026-58662
Improper Validation of Specified Quantity in Input, Out-of-bounds Read
vulnerability in Apache Thrift C++ bindings. This issue affects Apache
Thrift: before 0.24.0.

Backport patch to fix CVE-2026-58662.

Reference:
[https://nvd.nist.gov/vuln/detail/cve-2026-58662]

Upstream Patch:
[https://github.com/apache/thrift/commit/f961cdb44249c293fcce6a840ffa1f7419fd88d0]

Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:18 +05:30
Ankur Tyagi f311c7bdfc python3-django: upgrade 5.2.16 -> 5.2.17
Release Notes:
https://docs.djangoproject.com/en/dev/releases/5.2.17/

CVE: CVE-2026-15307 CVE-2026-15337 CVE-2026-15830 CVE-2026-15920

Backport Changes:
- Django 5.2.17 requires setuptools >= 83, the first
  upstream release containing the fix [1]. Wrynose provides
  setuptools 82.0.1 with that fix backported, so retain the
  previous build requirement.

[1] https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 8a4bf31e7f)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:17 +05:30
Devansh Patel 5250a6f557 python3-cbor2: use exact CVE_PRODUCT mapping
The product-only "cbor2" mapping uses a wildcard vendor. Use
"agronholm:cbor2", its NVD dictionary CPE and NVD configuration
identity for the packaged source.

The generated CPE changes, but Wrynose sbom-cve-check 1.3.1 with its
pinned 2026-05-07 databases has no current CVE report delta. This
backport applies the change to version 5.9.0 rather than 6.1.4.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 7f59d247ee)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:17 +05:30
Himanshu Jadon d7e93ab171 suitesparse: avoid install rpath buildpaths QA
SuiteSparse adds -Wl,-rpath=$(INSTALL_LIB) while linking shared
libraries on Linux. In the OpenEmbedded build this value can resolve to
a build or install path under TMPDIR, so installed ELF files can keep an
absolute build path and fail buildpaths QA.

The packaged libraries do not need this install-tree rpath. Runtime
resolution is handled through normal package dependencies and the target
library search path. Keep the librt link and drop only the rpath entry.

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 47037e87d5)
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:16 +05:30
Himanshu Jadon 5a65844a4e suitesparse: fix CMake 4 configure failure
SuiteSparse 5.10.1 still carries bundled CMake entry points with
2.x minimum versions. CMake 4 rejects projects which request
compatibility with versions older than 3.5, so configure fails before
SuiteSparse can build.

Backport the upstream SuiteSparse change which raises the bundled
Mongoose, METIS and GKlib minimum version to 3.13. This version also
reaches two bundled GraphBLAS CMake entry points with the same old
minimum, so update those in the backport as well.

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit de2fc817a4)
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:16 +05:30
Khem Raj 14282a02be libhtml-tree-perl, libmodule-build-tiny-perl: Drop obsolete TMPDIR scrubbing
oe-core 3c2bb7bce1 ("cpan_build: disable .packlist and html doc") moved
--create_packlist=0 into cpan_build.bbclass and disabled html doc
generation there as well. Neither .packlist nor the html docs are
generated anymore, so the do_install:append() hooks that sed'ed TMPDIR out
of them now run find(1) over paths that no longer exist and hand sed an
empty argument list:

  find: '.../image/usr/share/doc/perl/html/site/lib/HTML/': No such file or directory
  sed: no input files
  WARNING: exit code 4 from a shell command.

Remove the now dead hooks.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 9dc293d14d)
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-26 07:13:01 +05:30
Devansh Patel 4ddd1e3945 python3-httplib2: correct CVE_PRODUCT mapping
The current product-only "httplib2" mapping generates a wildcard-vendor
product identity instead of the vendor assigned to the packaged project.

Use "httplib2_project:httplib2" for its exact NVD dictionary CPE and NVD
configuration identity. This changes the generated CPE, but sbom-cve-check
1.3.3 with the pinned NVD database snapshot has no current CVE report delta.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 0a8f71a643)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 13:03:48 +05:30
Devansh Patel ecbab436e2 python3-web3: add CVE_PRODUCT mapping
The current inherited "python:web3" mapping does not match the web3.py identities used by NVD and CVE List V5, so its source-aligned CVE is missed.

Use "ethereum:web3.py" for the CNA affected-data identity and "apeworx:web3.py" for the NVD dictionary CPE and configuration identity.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 19ecb40f50)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 13:01:24 +05:30
Ankur Tyagi a02e847fa2 swagger-ui: upgrade 5.32.13 -> 5.32.14
Changelog:
https://github.com/swagger-api/swagger-ui/releases/tag/v5.32.14

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:12 +05:30
Khem Raj f136fe167f samba: upgrade 4.23.8 -> 4.23.11
Stay within the 4.23.x stable series (do not touch the sibling
talloc/tdb/tevent/ldb recipes). This picks up two intervening point
releases:

- 4.23.9: bug-fix release (use-after-free in ACL claims/conditions
  handling, CTDB read-only record use-after-free/resource leak, RODC
  auth fixes, among others).
- 4.23.10: security release fixing CVE-2026-6949 (TSIG/DNS OOB write
  crash), CVE-2026-58216 (KDC kpasswd OOB read crash),
  CVE-2026-58218 (DNS TKEY cache-flood DoS), CVE-2026-58221 (LDAP
  privilege escalation via internal LDB special DNs),
  CVE-2026-58222 (LDAP Compare filter used as protected-attribute
  disclosure oracle) and CVE-2026-58224 (CTDB protocol
  bounds-checking gaps).
- 4.23.11: further bug fixes (DRS memory leak, pthreadpool fork race,
  RODC/NTLMv2 trust fixes, CephFS vfs crashes).

All 13 existing patches (including the musl-only pam/getpwent_r ones)
still apply cleanly against 4.23.11 with offset only, no fuzz, so none
needed to be reworked or dropped. LIC_FILES_CHKSUM for COPYING is
unchanged.

Build-verified with cleansstate + full build for qemux86-64.

AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit f971f62ef1)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:12 +05:30
Wang Mingyu 56fc67a07e swagger-ui: upgrade 5.32.12 -> 5.32.13
Changelog:
===========
- a11y: add aria-labels to copy-to-clipboard buttons
- a11y: add skip-to-operations link, banner and main landmarks
- a11y: close Authorization popup with Escape key and backdrop click
- a11y: name and state for dark-mode toggle button
- a11y: restore icon visibility in Windows High Contrast Mode
- a11y: topbar logo and dark-mode toggle visible in HCM
- a11y: use for model titles to convey emphasis semantically
- ci: bump cycjimmy/semantic-release-action to v6.0.0
- ci: fix Trivy security scan and add dependency vulnerability scan
- style: reduce padding on inline code blocks in markdown

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit e0346def92)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:11 +05:30