diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.4.inc b/meta/recipes-kernel/linux/cve-exclusion_6.4.inc index 7bffaa70e1..eacb706a49 100644 --- a/meta/recipes-kernel/linux/cve-exclusion_6.4.inc +++ b/meta/recipes-kernel/linux/cve-exclusion_6.4.inc @@ -1,9 +1,9 @@ # Auto-generated CVE metadata, DO NOT EDIT BY HAND. -# Generated at 2023-09-30 07:22:32.115009+00:00 for version 6.4.15 +# Generated at 2023-09-30 07:24:59.900581+00:00 for version 6.4.16 python check_kernel_cve_status_version() { - this_version = "6.4.15" + this_version = "6.4.16" kernel_version = d.getVar("LINUX_VERSION") if kernel_version != this_version: bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) @@ -4796,7 +4796,7 @@ CVE_STATUS[CVE-2023-25012] = "fixed-version: Fixed from version 6.3rc1" CVE_STATUS[CVE-2023-2513] = "fixed-version: Fixed from version 6.0rc1" -# CVE-2023-25775 needs backporting (fixed from 6.4.16) +CVE_STATUS[CVE-2023-25775] = "cpe-stable-backport: Backported in 6.4.16" CVE_STATUS[CVE-2023-2598] = "fixed-version: Fixed from version 6.4rc1" @@ -4966,7 +4966,7 @@ CVE_STATUS[CVE-2023-3611] = "cpe-stable-backport: Backported in 6.4.5" # CVE-2023-3640 has no known resolution -# CVE-2023-37453 needs backporting (fixed from 6.4.16) +CVE_STATUS[CVE-2023-37453] = "cpe-stable-backport: Backported in 6.4.16" # CVE-2023-37454 has no known resolution @@ -5036,9 +5036,9 @@ CVE_STATUS[CVE-2023-4244] = "cpe-stable-backport: Backported in 6.4.12" CVE_STATUS[CVE-2023-4273] = "cpe-stable-backport: Backported in 6.4.10" -# CVE-2023-42752 needs backporting (fixed from 6.4.16) +CVE_STATUS[CVE-2023-42752] = "cpe-stable-backport: Backported in 6.4.16" -# CVE-2023-42753 needs backporting (fixed from 6.4.16) +CVE_STATUS[CVE-2023-42753] = "cpe-stable-backport: Backported in 6.4.16" CVE_STATUS[CVE-2023-42755] = "fixed-version: Fixed from version 6.3rc1" @@ -5060,7 +5060,7 @@ CVE_STATUS[CVE-2023-4611] = "cpe-stable-backport: Backported in 6.4.8" # CVE-2023-4622 needs backporting (fixed from 6.5rc1) -# CVE-2023-4623 needs backporting (fixed from 6.4.16) +CVE_STATUS[CVE-2023-4623] = "cpe-stable-backport: Backported in 6.4.16" # CVE-2023-4881 needs backporting (fixed from 6.6rc1) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.4.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.4.bb index 07e852d584..deb2eea73f 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.4.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.4.bb @@ -14,13 +14,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "40f6eb23017e1bb31c63e980b6d11bc8e917824b" -SRCREV_meta ?= "b1e8a40393e0ac784e05a45ee90b6680e3b53263" +SRCREV_machine ?= "61c6d869af5ffb90ac64095eafdf8ba513eb21a6" +SRCREV_meta ?= "13efe44fe9dd2626eaf6552288ea31770ec71cf1" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.4;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.4.15" +LINUX_VERSION ?= "6.4.16" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.4.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.4.bb index 74b830afb4..c81f230139 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.4.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.4.bb @@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.4.inc -LINUX_VERSION ?= "6.4.15" +LINUX_VERSION ?= "6.4.16" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "3f60b22a4257993a1e389d46d1204a0f580fc99e" -SRCREV_meta ?= "b1e8a40393e0ac784e05a45ee90b6680e3b53263" +SRCREV_machine ?= "ef91ff6a4be36037808af1ca786fdd557f265a1d" +SRCREV_meta ?= "13efe44fe9dd2626eaf6552288ea31770ec71cf1" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.4.bb b/meta/recipes-kernel/linux/linux-yocto_6.4.bb index d17f05eba4..5afd7b1ba7 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.4.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.4.bb @@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.4/standard/base" KBRANCH:qemuloongarch64 ?= "v6.4/standard/base" KBRANCH:qemumips64 ?= "v6.4/standard/mti-malta64" -SRCREV_machine:qemuarm ?= "47cff83414374714b911719ba588aa6e2816956b" -SRCREV_machine:qemuarm64 ?= "3f60b22a4257993a1e389d46d1204a0f580fc99e" -SRCREV_machine:qemuloongarch64 ?= "3f60b22a4257993a1e389d46d1204a0f580fc99e" -SRCREV_machine:qemumips ?= "d3a6c87612629a4c1f722b7d93e9a04aec7b22a4" -SRCREV_machine:qemuppc ?= "3f60b22a4257993a1e389d46d1204a0f580fc99e" -SRCREV_machine:qemuriscv64 ?= "3f60b22a4257993a1e389d46d1204a0f580fc99e" -SRCREV_machine:qemuriscv32 ?= "3f60b22a4257993a1e389d46d1204a0f580fc99e" -SRCREV_machine:qemux86 ?= "3f60b22a4257993a1e389d46d1204a0f580fc99e" -SRCREV_machine:qemux86-64 ?= "3f60b22a4257993a1e389d46d1204a0f580fc99e" -SRCREV_machine:qemumips64 ?= "da59fe1c279b1be0b6b51dc503fe6500fdf84671" -SRCREV_machine ?= "3f60b22a4257993a1e389d46d1204a0f580fc99e" -SRCREV_meta ?= "b1e8a40393e0ac784e05a45ee90b6680e3b53263" +SRCREV_machine:qemuarm ?= "871a4762a8f85550898b8992b29d5e1dbf60a459" +SRCREV_machine:qemuarm64 ?= "ef91ff6a4be36037808af1ca786fdd557f265a1d" +SRCREV_machine:qemuloongarch64 ?= "ef91ff6a4be36037808af1ca786fdd557f265a1d" +SRCREV_machine:qemumips ?= "18bb71cbb388dd093c46d1777f607cfbf0d4c03b" +SRCREV_machine:qemuppc ?= "ef91ff6a4be36037808af1ca786fdd557f265a1d" +SRCREV_machine:qemuriscv64 ?= "ef91ff6a4be36037808af1ca786fdd557f265a1d" +SRCREV_machine:qemuriscv32 ?= "ef91ff6a4be36037808af1ca786fdd557f265a1d" +SRCREV_machine:qemux86 ?= "ef91ff6a4be36037808af1ca786fdd557f265a1d" +SRCREV_machine:qemux86-64 ?= "ef91ff6a4be36037808af1ca786fdd557f265a1d" +SRCREV_machine:qemumips64 ?= "5b9def2ea1065e44847b920c3a4185d0e5c22d58" +SRCREV_machine ?= "ef91ff6a4be36037808af1ca786fdd557f265a1d" +SRCREV_meta ?= "13efe44fe9dd2626eaf6552288ea31770ec71cf1" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "f60d5fd5e950c89a38578ae6f25877de511bb031" +SRCREV_machine:class-devupstream ?= "ae4e4fc35b4258626644c162a702e2bce2b79190" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.4/base" @@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.4;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.4.15" +LINUX_VERSION ?= "6.4.16" PV = "${LINUX_VERSION}+git"