On Wed Jul 15, 2026 at 7:21 PM CEST, Deepak Rathore via lists.openembedded.org 
wrote:
> From: Deepak Rathore <[email protected]>
>
> This patch applies the upstream 2.88.1 backport for
> CVE-2026-58010. The upstream fix commit is referenced in [1],
> and the public CVE advisory is referenced in [2].
>
> [1] 
> https://gitlab.gnome.org/GNOME/glib/-/commit/be85f9429bb66412a9775440a88cb115803ba897
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58010
>
> Signed-off-by: Deepak Rathore <[email protected]>

Hello Deepak and Adarsh,

You both sent backport patches for this CVE.

This CVE (and I bet others of this series) can be fixed by upgrading
along the 2.88.x branch of glib. There are precedent for glib upgrade on
stable branches.

Can you look into the glib changelog and see if there are changes
incompatible with our policy?

If upgrading is compatible, please tell me and I will cherry pick the
upgrades from master:
glib-2.0: Upgrade 2.88.0 -> 2.88.1
https://git.openembedded.org/openembedded-core/commit/?id=e2063c252d1ab3188e74e9eced91bc17463d6551
glib-2.0: upgrade 2.88.1 -> 2.88.2
https://git.openembedded.org/openembedded-core/commit/?id=c22a7bd7ecb463da212c25a5aa81a19992e17e1c

If not, ping me as well, I will then resume reviewing this series.

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#241207): 
https://lists.openembedded.org/g/openembedded-core/message/241207
Mute This Topic: https://lists.openembedded.org/mt/120285725/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to