On Sat Sep 26, 2026 at 10:49 PM CEST, Yoann Congal wrote:
> On Wed Aug 26, 2026 at 12:17 PM CEST, Omkar Patil via lists.openembedded.org 
> wrote:
>> From: Peter Marko <[email protected]>
>>
>> Solves CVE-2026-33846, CVE-2026-42009, CVE-2026-33845, CVE-2026-42010,
>> CVE-2026-3833, CVE-2026-42011, CVE-2026-42012, CVE-2026-42013,
>> CVE-2026-42014, CVE-2026-5260, CVE-2026-42015, CVE-2026-3832 and
>> CVE-2026-5419.
>>
>> Release notes: [1]
>>
>> Rebase patches and drop patch included in this release.
>> Add patches to fix linking with musl libc.
>> Increase memory needed to successfully run test key-openssl.
>> Drop code for previous release tarball problem.
>>
>> [1] https://github.com/gnutls/gnutls/blob/3.8.13/NEWS
>>
>> Signed-off-by: Peter Marko <[email protected]>
>> Signed-off-by: Mathieu Dubois-Briand <[email protected]>
>> Signed-off-by: Richard Purdie <[email protected]>
>> Signed-off-by: Omkar Patil <[email protected]>
>> ---
>>  meta/recipes-core/images/core-image-ptest.bb  |   2 +
>>  ...fragments-implement-a-basic-DTLS-tes.patch | 258 ------------------
>>  ...s-mini-dtls-framents-link-to-gnulib.patch} |  12 +-
>>  ...ust-list-fault-fix-issues-in-linking.patch |  31 +++
>>  ...merge_handshake_packet-using-recv_bu.patch |  96 -------
>>  ...s-add-more-checks-to-DTLS-reassembly.patch |  65 -----
>>  ...fragments-extend-with-a-1816-reprodu.patch | 159 -----------
>>  ...fragments-extend-with-fragmenting-Cl.patch | 149 ----------
>>  ...ch-DTLS-datagrams-by-sequence-number.patch |  42 ---
>>  ...fragments-1839-mismatching-message_s.patch | 104 -------
>>  .../gnutls/gnutls/Add-ptest-support.patch     |   4 +-
>>  .../gnutls/gnutls/CVE-2026-3832_p1.patch      |  52 ----
>>  .../gnutls/gnutls/CVE-2026-3832_p2.patch      | 114 --------
>>  .../gnutls/gnutls/CVE-2026-3833.patch         |  90 ------
>>  .../gnutls/gnutls/CVE-2026-42009_p1.patch     |  62 -----
>>  .../gnutls/gnutls/CVE-2026-42009_p2.patch     |  48 ----
>>  meta/recipes-support/gnutls/gnutls/c99.patch  |  41 ---
>>  .../{gnutls_3.8.12.bb => gnutls_3.8.13.bb}    |  22 +-
>>  18 files changed, 43 insertions(+), 1308 deletions(-)
>>  delete mode 100644 
>> meta/recipes-support/gnutls/gnutls/0001-tests-mini-dtls-fragments-implement-a-basic-DTLS-tes.patch
>>  rename 
>> meta/recipes-support/gnutls/gnutls/{0008-tests-mini-dtls-framents-link-to-gnulib.patch
>>  => 0001-tests-mini-dtls-framents-link-to-gnulib.patch} (68%)
>>  create mode 100644 
>> meta/recipes-support/gnutls/gnutls/0001-tests-pkcs11-trust-list-fault-fix-issues-in-linking.patch
>>  delete mode 100644 
>> meta/recipes-support/gnutls/gnutls/0002-buffers-shorten-merge_handshake_packet-using-recv_bu.patch
>>  delete mode 100644 
>> meta/recipes-support/gnutls/gnutls/0003-buffers-add-more-checks-to-DTLS-reassembly.patch
>>  delete mode 100644 
>> meta/recipes-support/gnutls/gnutls/0004-tests-mini-dtls-fragments-extend-with-a-1816-reprodu.patch
>>  delete mode 100644 
>> meta/recipes-support/gnutls/gnutls/0005-tests-mini-dtls-fragments-extend-with-fragmenting-Cl.patch
>>  delete mode 100644 
>> meta/recipes-support/gnutls/gnutls/0006-buffers-match-DTLS-datagrams-by-sequence-number.patch
>>  delete mode 100644 
>> meta/recipes-support/gnutls/gnutls/0007-tests-mini-dtls-fragments-1839-mismatching-message_s.patch
>>  delete mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-3832_p1.patch
>>  delete mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-3832_p2.patch
>>  delete mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-3833.patch
>>  delete mode 100644 
>> meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch
>>  delete mode 100644 
>> meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch
>>  delete mode 100644 meta/recipes-support/gnutls/gnutls/c99.patch
>>  rename meta/recipes-support/gnutls/{gnutls_3.8.12.bb => gnutls_3.8.13.bb} 
>> (78%)
>
> Hello,
>
> Sorry, this upgrade was requested (and rejected) before:
> See 
> https://lore.kernel.org/all/[email protected]/
>
> Regards,

That said, we might consider this upgrade if that solves a problem that
is otherwise too hard to do (like patches hard to backport) and simplify
maintenance.

(@Haixiao Yan, @Vijay Anusuri: you also sent this upgrade request)

@All: Is there a reason why you sent the upgrade instead of the
backports? (I guess the reason you had could be a justification for the
upgrade exception)

Thanks,
-- 
Yoann Congal
Smile ECS
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246977): 
https://lists.openembedded.org/g/openembedded-core/message/246977
Mute This Topic: https://lists.openembedded.org/mt/120934740/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to