Please review this set of changes for scarthgap and have comments back by end of day Thursday, August 27.
Passed a-full on autobuilder: https://autobuilder.yoctoproject.org/valkyrie/?#/builders/29/builds/4569 The following changes since commit 70dc15941dd33270a92d1001174efb3093e79bdf: build-appliance-image: Update to scarthgap head revision (2026-08-24 14:28:47 +0100) are available in the Git repository at: https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut for you to fetch changes up to b7007d82eec734bab6760ae325645ae5b199e384: rpcbind: Fix CVE-2026-16277 (2026-08-25 07:01:14 +0200) ---------------------------------------------------------------- Adarsh Jagadish Kamini (1): libssh2: fix CVE-2026-58050 Deepak Rathore (2): nghttp2: set status for CVE-2026-58055 glib-2.0: fix CVE-2026-58015 Etienne Cordonnier (1): curl: fix CVE-2025-10148 backport for websockets on 8.7.1 Jaipaul Cheernam (4): binutils: fix CVE-2025-1147 binutils: fix CVE-2025-8224 binutils: fix CVE-2026-15003 binutils: fix CVE-2026-18220 Peter Marko (1): bison: patch CVE-2026-56389 Ross Burton (1): bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES Vijay Anusuri (1): rpcbind: Fix CVE-2026-16277 meta/conf/bitbake.conf | 6 +- .../glib-2.0/glib-2.0/CVE-2026-58015_p1.patch | 97 +++++ .../glib-2.0/glib-2.0/CVE-2026-58015_p2.patch | 55 +++ .../glib-2.0/glib-2.0/CVE-2026-58015_p3.patch | 198 +++++++++ .../glib-2.0/glib-2.0/CVE-2026-58015_p4.patch | 222 ++++++++++ meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 4 + meta/recipes-core/glib-2.0/glib.inc | 2 +- .../binutils/binutils-2.42.inc | 4 + .../binutils/binutils/CVE-2025-1147.patch | 110 +++++ .../binutils/binutils/CVE-2025-8224.patch | 54 +++ .../binutils/binutils/CVE-2026-15003.patch | 400 ++++++++++++++++++ .../binutils/binutils/CVE-2026-18220.patch | 65 +++ .../bison/bison/CVE-2026-56389.patch | 56 +++ meta/recipes-devtools/bison/bison_3.8.2.bb | 1 + .../rpcbind/rpcbind/CVE-2026-16277.patch | 34 ++ .../recipes-extended/rpcbind/rpcbind_1.2.6.bb | 1 + .../curl/curl/CVE-2025-10148.patch | 24 +- .../libssh2/libssh2/CVE-2026-58050.patch | 45 ++ .../recipes-support/libssh2/libssh2_1.11.1.bb | 1 + .../recipes-support/nghttp2/nghttp2_1.61.0.bb | 2 + 20 files changed, 1367 insertions(+), 14 deletions(-) create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch create mode 100644 meta/recipes-devtools/bison/bison/CVE-2026-56389.patch create mode 100644 meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244215): https://lists.openembedded.org/g/openembedded-core/message/244215 Mute This Topic: https://lists.openembedded.org/mt/120917938/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
