On 2023-01-16 10:20, Kokkonda, Sundeep via lists.openembedded.org wrote:
Rust community said the security fixes are only for the current stable relases.
https://internals.rust-lang.org/t/cargo-cve-2022-46176-fix-for-older-releases/18152/3?u=sundeep-kokkonda
For old release we've to backport the patches ourselves.

The other alternatives are

1. upgrade to 1.66.1 on older branches,

2. add 1.66.1, which will be the PREFERRED_VERSION but keep the older version for those who are risk averse,

3. add a mix-in layer (1) with the upgrade to 1.66.1.

For langdale, we'd update from 1.63 and for kirkstone, we'd update from 1.59

See the link above for a discussion about what Fedora/RHEL and other distros are doing and a description of the rust / crates.io test system known as crater that builds the
world for any significant rust change.


Is there any objection to doing 2 and if we don't see any problems after some time,
then removing the older version?

Sundeep,

If no one object, please update kirkstone and see if librsvg or python-cryptography or
anything else encounters a problem.

../Randy


1) https://wiki.yoctoproject.org/wiki/Stable_Release_and_LTS#LTS_.E2.80.9CMixin.E2.80.9D_repositories


So, for the Kirkstone & Langdale we've to back port the CVE fix.




--
# Randy MacLeod
# Wind River Linux
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#176061): 
https://lists.openembedded.org/g/openembedded-core/message/176061
Mute This Topic: https://lists.openembedded.org/mt/96218038/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to