Wang Mingyu
f05ea82cd6
python3-tzdata: upgrade 2026.2 -> 2026.3
...
License-Update: Copyright year updated to 2026
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit ea00a3bf35 )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:14 +05:30
Wang Mingyu
dd30c3946b
proftpd: upgrade 1.3.9b -> 1.3.9c
...
Changelog:
===========
- Issue 2135 - ExecEnviron values not passed due to regression since 1.3.8.d.
- Issue 2146 - Stack buffer overflow in MLSD/MLST handling for long path names.
- Issue 2158 - MaxTransfersPerUser no longer enforces configured limits.
- Issue 2163 - AdminControlsACLs for config, get actions not honored as they
should be.
- Issue 2166 - Memcached/Redis-cached JSON TLS session/OCSP entries decoded
into fixed buffers without bounds checking.
- Issue 2173 - RewriteMap unescape builtin use causes one-byte out-of-bounds
write, fails to reject illegal characters.
- Issue 2188 - SQL group name lookup concatenates client-provided group names
without escaping.
- Issue 2190 - Authenticated SFTP sessions can overflow the SFTP packet buffer.
- Issue 2210 - Default Controls socket ACLs unintentionally allow all users
access for sending Controls requests.
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit c13b1c4115 )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:13 +05:30
Khem Raj
b618f4a5f8
samba: upgrade 4.23.5 -> 4.23.8
...
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 7840b777e1 )
Security release https://gitlab.com/samba-team/samba/-/blob/samba-4.23.8/WHATSNEW.txt?ref_type=tags
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:13 +05:30
Khem Raj
990b4317f5
apache2: upgrade 2.4.67 -> 2.4.68
...
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 23cdc4ca43 )
Changelog:
https://downloads.apache.org/httpd/CHANGES_2.4.68
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:12 +05:30
Khem Raj
649e756817
xdebug: upgrade 3.5.1 -> 3.5.3
...
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 779cef925d )
Changelog:
https://xdebug.org/updates#x_3_5_3
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:12 +05:30
Wang Mingyu
991c8bbf59
monocypher: upgrade 4.0.2 -> 4.0.3
...
Changelog:
===========
- Fixed timing leak vulnerability in EdDSA/Ed25519 signatures.
- Various minor documentation fixes.
- Various minor build system fixes.
- Various minor compiler warning fixes.
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 25cfd0324c )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:12 +05:30
Khem Raj
a570a69a24
ifuse: upgrade 1.2.0 -> 1.2.1
...
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit a2ab019840 )
Changelog:
https://github.com/libimobiledevice/ifuse/releases/tag/1.2.1
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:11 +05:30
Wang Mingyu
c626518243
python3-socketio: upgrade 5.16.2 -> 5.16.3
...
Changelog:
Catch all exceptions in redis and rabbitmq client managers
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 2ffa73965f )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:11 +05:30
Wang Mingyu
fed0f3fa73
python3-socketio: upgrade 5.16.1 -> 5.16.2
...
Changelog:
===========
- Prevent unnecessary resource allocations
- Add zizmor to CI builds
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 9b8bf4de6f )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:10 +05:30
Wang Mingyu
796c5eef13
python3-sqlalchemy: upgrade 2.0.50 -> 2.0.51
...
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 1b4d3a7617 )
Changelog:
https://docs.sqlalchemy.org/en/21/changelog/changelog_20.html#change-2.0.51
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:10 +05:30
Wang Mingyu
f9e9e33f9e
python3-sqlalchemy: upgrade 2.0.49 -> 2.0.50
...
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit c419e48aa3 )
Changelog:
https://docs.sqlalchemy.org/en/21/changelog/changelog_20.html#change-2.0.50
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:09 +05:30
Wang Mingyu
58328627df
libnvme: upgrade 1.16.1 -> 1.16.2
...
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 83c7ce82cf )
Changelog:
https://github.com/linux-nvme/libnvme/releases/tag/v1.16.2
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:09 +05:30
Wang Mingyu
0ecf94217d
swagger-ui: upgrade 5.32.7 -> 5.32.8
...
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 39399bd1e4 )
Changelog:
https://github.com/swagger-api/swagger-ui/releases/tag/v5.32.8
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:08 +05:30
Wang Mingyu
40f4c23f3e
swagger-ui: upgrade 5.32.6 -> 5.32.7
...
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 5a1603e21d )
Changelog:
https://github.com/swagger-api/swagger-ui/releases/tag/v5.32.7
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:08 +05:30
Markus Volk
fe9c4efc8e
pipewire: update 1.6.7 -> 1.6.8
...
PipeWire 1.6.8 (2026-07-09)
This is a bugfix release that is API and ABI compatible with the previous
1.6.x releases.
Highlights
- Fix a data race in JACK that could cause lost MIDI events in ardour.
- Fix some unbounded memory allocations.
- Various small fixes.
PipeWire
- Avoid some graph recalcs, which fixes a bug when suspending a node
while it is active.
Modules
- Do Content-Length and allocation check in RAOP to avoid OOM errors.
- Fix a potential memory leak in the error path of client-node. (#5348 )
SPA
- Fix filter-graph dynamic graph updates.
- Avoid 100% when unplugging a card.
- Fix filter-graph volumes when the filter is loaded inside a node with
hardware volume. (#5344 )
- Add normalize and latency options to the SOFA filter. (#5322 )
Bluetooth
- Fix a potential leak when transport fails to start.
Pulse-server
- Avoid stack exhaustion via unbounded alloca.
JACK
- Fix a data race in jack_port_get_buffer() when called from concurrent
threads, like in ardour. (#5324 )
GStreamer
- Skip invalid crop metadata.
- Avoid crash because metadata listener was registered twice.
Signed-off-by: Markus Volk <f_l_k@t-online.de >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 6dbf718454 )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:07 +05:30
Markus Volk
7ab7f6c445
pipewire: update 1.6.6 -> 1.6.7
...
PipeWire 1.6.7 (2026-06-18)
This is a bugfix release that is API and ABI compatible with the previous
1.6.x releases.
Highlights
- Fix a race issue where some ports would stay silent after a rate change.
- Fix sync regressions between ALSA cards in some cases.
- Small fixes and improvements.
PipeWire
- Fix a scheduler regression where some driver nodes would not run
correctly and cause sync issues. (#5210 )
- Fix a race issue with suspend on samplerate changes. It can cause ports
to be silent. (#3547 )
Modules
- There are some locking issues in the RT portal, for now reduce the
DBus timeout to something more sane. Also disable portal RT for
pipewire and the pulse server. These are not usually run in a sandbox
and can go directly to RTKit.
- Fix potential incorrect delay in combine-stream.
SPA
- Fix a regression in ALSA period_size calculations. For non-power-of-2
periods, it would in some cases round down a a power-of-2, causing a
mismatch between requested and configured period_size. (#5302 )
- Fix a potential segfault when removing a card because of bad ALSA api
usage. (#5255 )
- Emit a route param update when card properties change. Otherwise, jack
port updates are not always reflected correctly.
Misc
- Make sure we don't deal with uninitialized spa_dict.
Signed-off-by: Markus Volk <f_l_k@t-online.de >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit ce604315bc )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:07 +05:30
Wang Mingyu
f64cb61c70
python3-elementpath: upgrade 5.1.2 -> 5.1.3
...
Changelog:
Fix protection against type cast errors during the static analysis phase
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 90866b4b09 )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:06 +05:30
Wang Mingyu
c247e7f560
python3-elementpath: upgrade 5.1.1 -> 5.1.2
...
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 4cb8410f9b )
Changelog:
https://github.com/sissaschool/elementpath/releases/tag/v5.1.2
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:06 +05:30
Leon Anavi
b03a692c8c
python3-tornado: Upgrade 6.5.6 -> 6.5.7
...
Upgrade to release 6.5.7:
- CurlAsyncHTTPClient now fully resets the curl object before reusing
it. This prevents incorrectly reusing options from a previous request,
specifically including client SSL and credentials used for accessing
proxies.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 7c11942641 )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:06 +05:30
Wang Mingyu
6e0f83c50c
python3-tornado: upgrade 6.5.5 -> 6.5.6
...
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 7efb03070d )
ReleaseNotes:
https://www.tornadoweb.org/en/stable/releases/v6.5.6.html
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:05 +05:30
Wang Mingyu
692717b940
imagemagick: upgrade 7.1.2-26 -> 7.1.2-27
...
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit c63bd731e4 )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:05 +05:30
Wang Mingyu
871964d413
imagemagick: upgrade 7.1.2-25 -> 7.1.2-26
...
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 1078fc88a3 )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:04 +05:30
Wang Mingyu
a67de14c51
imagemagick: upgrade 7.1.2-24 -> 7.1.2-25
...
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 9775e7d42b )
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:04 +05:30
Peter Marko
d743f51536
libcoap: set status for CVE-2023-51847
...
Reuse investigation of Debian security group.
As mentioned by [1], this was never present in any release because it
was introduces in 4.3.5 development, however also fixed before release.
[1] https://security-tracker.debian.org/tracker/CVE-2023-51847
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:03 +05:30
Peter Marko
cfad06b7d8
tcpdump: set status for CVE-2024-2397
...
This CVE is fixed with commit [1] included in release 4.99.5.
It is a cherry-pick of commit [2] mentioned in NVD report [3].
cvelistV5 and FKIE list hash as fixed version ("lessThan": "b9811ef"),
which causes a false positive thus needs to be handled explicitly.
[1] https://github.com/the-tcpdump-group/tcpdump/commit/e9bff173f9833b5532f3b6dce8c049e955140169
[2] https://github.com/the-tcpdump-group/tcpdump/commit/b9811ef5bb1b7d45a90e042f81f3aaf233c8bcb2
[3] https://nvd.nist.gov/vuln/detail/CVE-2024-2397
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:03 +05:30
Peter Marko
15ea815f61
python3-protobuf: set status for CVE-2024-7254
...
Version 4.28.2 is correctly set in [1].
Unfortunately also protoc version 28.2 with the same CPE is mentioned
which creates a false positive which needs to be handled.
[1] https://github.com/CVEProject/cvelistV5/blob/main/cves/2024/7xxx/CVE-2024-7254.json
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:02 +05:30
Peter Marko
a61a69e40e
protobuf: set status for CVE-2024-7254
...
Version 4.28.2 is correctly set in [1].
Unfortunately also protoc version 28.2 with the same CPE is mentioned
which creates a false positive which needs to be handled.
[1] https://github.com/CVEProject/cvelistV5/blob/main/cves/2024/7xxx/CVE-2024-7254.json
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:02 +05:30
Peter Marko
584a16a0b7
python3-grpcio: set status for CVE-2023-33953 and CVE-2024-37168
...
CVE-2023-33953 is fixed since 1.56.2 per [1].
FKIE sets "defaultStatus": "unknown" so it needs to be set explicitly.
CVE-2024-37168 description in [2] says grpc-js.
Even if (like FKIE added) grpc core would be affected, it would be in
old versions (also listed in [2]).
[1] https://nvd.nist.gov/vuln/detail/CVE-2023-33953
[2] https://nvd.nist.gov/vuln/detail/CVE-2024-37168
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:01 +05:30
Peter Marko
7cf2ece441
grpc: set status for CVE-2023-33953 and CVE-2024-37168
...
CVE-2023-33953 is fixed since 1.56.2 per [1].
FKIE sets "defaultStatus": "unknown" so it needs to be set explicitly.
CVE-2024-37168 description in [2] says grpc-js.
Even if (like FKIE added) grpc core would be affected, it would be in
old versions (also listed in [2]).
[1] https://nvd.nist.gov/vuln/detail/CVE-2023-33953
[2] https://nvd.nist.gov/vuln/detail/CVE-2024-37168
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:01 +05:30
Darsh Kelaiya
f4c7a41fda
jq: Fix CVE-2026-54679
...
This patch applies the upstream fix for CVE-2026-54679 as referenced
in [2], using the upstream commit identified in [1].
[1] https://github.com/jqlang/jq/commit/46d1da30944ce93dd671ac72b6513fc0eb747837
[2] https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:00 +05:30
Darsh Kelaiya
f2fafaf4eb
jq: Fix CVE-2026-49839
...
This patch applies the upstream fix for CVE-2026-49839 as referenced
in [2], using the upstream commit identified in [1].
[1] https://github.com/jqlang/jq/commit/e987df0d463d85fd70825e042a082427e8275b86
[2] https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:00 +05:30
Darsh Kelaiya
99f7ee0390
jq: Fix CVE-2026-43895
...
This patch applies the upstream fix as referenced in [2], using the commit shown in [1].
[1] https://github.com/jqlang/jq/commit/9d223f153c3632a207fa071caaa6292da33ae361
[2] https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:33:00 +05:30
Peter Marko
b769133423
c-ares: set status for CVE-2025-31498
...
This CVE was fixed in 1.34.5 as mentioned in release notes [1].
[1] https://github.com/c-ares/c-ares/releases/tag/v1.34.5
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:32:59 +05:30
Jason Schonberg
0a7293510e
c-ares: upgrade 1.34.6 -> 1.34.8
...
Version 1.34.8 is a bug fix (a regression that shipped with version 1.34.7)
Version 1.34.7 is a security fix addressing memory leaks, null pointer
dereferences, denial of service, use after free etc. Fixes CVE-2026-33630
Changelog: https://github.com/c-ares/c-ares/releases/tag/v1.34.8
Changelog: https://github.com/c-ares/c-ares/releases/tag/v1.34.7
Signed-off-by: Jason Schonberg <schonm@gmail.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(From meta-oe rev: 0770ef4043 )
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:32:59 +05:30
Peter Marko
f2f25d7d2d
bit7z: set status for CVE-2026-45380 and CVE-2026-45384
...
These CVEs were fixed in 4.0.12 as seen in release notes [1].
Current CVE-CHECK still reports them as unfixed, correct it.
[1] https://github.com/rikyoz/bit7z/releases/tag/v4.0.12
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:32:58 +05:30
Peter Marko
1410436f6a
7zip: set status for CVE-2026-58052
...
Per Debian team investogations, this can only occur on Windows.
See main CVE page [1] which links to detailed explanation [2].
[1] https://security-tracker.debian.org/tracker/CVE-2026-58052
[2] https://lists.debian.org/debian-lts/2026/07/msg00038.html
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:32:58 +05:30
Peter Marko
5f4a0f63a5
libwebsockets: patch CVE-2026-10650
...
Pick patch mentioned in NVD report.
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:31:18 +05:30
Peter Marko
4aa61e22bd
libwebsockets: set status for CVE-2025-1866
...
Current cve-check code does not correctly decode the entry [1]:
"versions": [
{
"changes": [
{
"at": "patch 4.3.4",
"status": "unaffected"
}
],
"lessThan": "<4.3.4",
"status": "affected",
"version": "0",
"versionType": "git"
}
]
[1] https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/1xxx/CVE-2025-1866.json
Signed-off-by: Peter Marko <peter.marko@siemens.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:31:18 +05:30
Deepak Rathore
0038cec53f
mbedtls: set CVE_STATUS for CVE-2025-66442
...
Analysis:
- The Mbed TLS advisory states the issue occurs when LLVM
select-optimize is enabled. [1]
- The same advisory also states that Arm/x86 builds with
MBEDTLS_HAVE_ASM enabled are not affected. The default mbedtls
configuration in this branch enables MBEDTLS_HAVE_ASM.
- NVD also describes the issue as occurring only with LLVM's
select-optimize feature. [2]
- The mbedtls recipes now evaluate the effective build flags across
target, native, and nativesdk variants, handle the supported
-mllvm spellings, and only mark the CVE unpatched when the
vulnerable LLVM option combination is explicitly enabled and the
Arm/x86 MBEDTLS_HAVE_ASM carve-out does not apply.
- When those conditions are not met, the current mbedtls build
configuration is not affected.
- Hence ignoring/deferred the CVE for now.
Reference:
[1] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-compiler-induced-constant-time-violations/
[2] https://nvd.nist.gov/vuln/detail/CVE-2025-66442
Signed-off-by: Deepak Rathore <deeratho@cisco.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
(cherry picked from commit 0eda0f3c55 )
Signed-off-by: Deepak Rathore <deeratho@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:31:17 +05:30
Deepak Rathore
127cbcea49
libidn: Fix CVE-2026-57053
...
This patch applies the upstream v1.44 backport for
CVE-2026-57053. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://git.savannah.gnu.org/cgit/libidn.git/commit/?id=f57fab06afc1e328bbe197ad3d4a4e83c829593e
[2] https://www.cve.org/CVERecord?id=CVE-2026-57053
Signed-off-by: Deepak Rathore <deeratho@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:31:17 +05:30
Deepak Rathore
0b5f9bd6ab
nmap: Fix CVE-2026-58058
...
This patch applies the upstream master backport for
CVE-2026-58058. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83
[2] https://github.com/advisories/GHSA-wxvj-hc4r-fq45
Signed-off-by: Deepak Rathore <deeratho@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:31:16 +05:30
Roland Kovacs
8cba40ff88
radvd: fix CVE-2026-48715
...
Prior to version 2.21, the `radvdump` utility shipped with radvd
contains a stack buffer overflow in the Route Information option
parser.
When processing a crafted ICMPv6 Router Advertisement, `print_ff()`
copies up to 2032 bytes from attacker-controlled packet data into a
16-byte `struct in6_addr` on the stack, overflowing by up to 2016
bytes.
Signed-off-by: Roland Kovacs <roland.kovacs@est.tech >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:31:16 +05:30
Roland Kovacs
0a044f3363
thrift: fix multiple CVEs
...
CVE-2026-43868:
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.
CVE-2026-43869:
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This CVE only affects the Java client, which is not built by the recipe. Marked as
'not-applicable-config'.
Upstream commit:
https://github.com/apache/thrift/commit/a30c552bd0808b7e19f35ad30212ba7a9aee8c66
CVE-2026-43870:
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers
('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability
in Apache Thrift.
Signed-off-by: Roland Kovacs <roland.kovacs@est.tech >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-22 06:31:15 +05:30
Qliangw
d97b5602d7
libuio: fix FILE descriptor leak
...
The function uio_line_from_file() fails to close the FILE pointer
when fgets() returns NULL, causing a file descriptor leak.
This can be triggered when reading from /sys files that return
empty content, leading to resource exhaustion over time.
Fix this by using goto-based error handling to ensure fclose()
is called on all exit paths.
Signed-off-by: Qliangw <qili00001@gmail.com >
(cherry picked from commit cd75edf25d )
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-07 08:04:43 +05:30
Shubham Pushpkar
532ac37990
jq: Fix CVE-2026-44777
...
The upstream fix [3] is for a newer jq codebase. Debian has already
backported this fix in jq 1.8.1-7. Use the Debian patch [1], which fixes
this CVE as tracked in Debian bug #1136445 [2].
[1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-44777.patch
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445
[3] https://github.com/jqlang/jq/commit/f58787c41835d9b17795730cb04925fdba25c71c
Signed-off-by: Shubham Pushpkar <spushpka@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-07 08:02:38 +05:30
Shubham Pushpkar
22b6fca850
jq: Fix CVE-2026-43896
...
The upstream fix [3] is for a newer jq codebase. Debian has already
backported this fix in jq 1.8.1-7. Use the Debian patch [1], which fixes
this CVE as tracked in Debian bug #1136445 [2].
[1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-43896.patch
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445
[3] https://github.com/jqlang/jq/commit/532ccea6080ed6758f39fe9f6208a44b665023d2
Reference:
https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846
Signed-off-by: Shubham Pushpkar <spushpka@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-07 08:02:37 +05:30
Shubham Pushpkar
febf27765f
jq: Fix CVE-2026-43894
...
The upstream fix [3] is for a newer jq codebase. Debian has already
backported this fix in jq 1.8.1-7. Use the Debian patch [1], which fixes
this CVE as tracked in Debian bug #1136445 [2].
[1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-43894.patch
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445
[3] https://github.com/jqlang/jq/commit/9761ceb7d6cc48c16b25f0ab1baaef0e701927e4
Reference:
https://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g
Signed-off-by: Shubham Pushpkar <spushpka@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-07 08:02:37 +05:30
Shubham Pushpkar
6c7344594c
jq: Fix CVE-2026-41257
...
The upstream fix [3] is for a newer jq codebase. Debian has already
backported this fix in jq 1.8.1-6. Use the Debian patch [1], which fixes
this CVE as tracked in Debian bug #1136445 [2].
[1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-41257.patch
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445
[3] https://github.com/jqlang/jq/commit/01b3cded76daacbfddb7f8763700b0803bcb5c6f
Signed-off-by: Shubham Pushpkar <spushpka@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-07 08:02:36 +05:30
Shubham Pushpkar
5a3f41fa6f
jq: Fix CVE-2026-41256
...
The upstream fix [3] is for a newer jq codebase. Debian has already
backported this fix in jq 1.8.1-6. Use the Debian patch [1], which fixes
this CVE as tracked in Debian bug #1136445 [2].
[1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-41256.patch
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445
[3] https://github.com/jqlang/jq/commit/5a015deae35d19e3ebbc65db6c157a80e76df738
Reference:
https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg
Signed-off-by: Shubham Pushpkar <spushpka@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-07 08:02:36 +05:30
Shubham Pushpkar
6a3d681278
jq: Fix CVE-2026-40612
...
The upstream fix [3] is for a newer jq codebase. Debian has already
backported this fix in jq 1.8.1-6. Use the Debian patch [1], which fixes
this CVE as tracked in Debian bug #1136445 [2].
[1] https://sources.debian.org/src/jq/1.8.1-7/debian/patches/CVE-2026-40612.patch
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136445
[3] https://github.com/jqlang/jq/commit/d1a12569d91641135976a8536776a4a329c02cc2
Reference:
https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j
Signed-off-by: Shubham Pushpkar <spushpka@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-07-07 08:02:36 +05:30