Please review this set of changes for scarthgap and have comments back by
end of day Thursday, August 27.

Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/29/builds/4569

The following changes since commit 70dc15941dd33270a92d1001174efb3093e79bdf:

  build-appliance-image: Update to scarthgap head revision (2026-08-24 14:28:47 
+0100)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
  
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut

for you to fetch changes up to b7007d82eec734bab6760ae325645ae5b199e384:

  rpcbind: Fix CVE-2026-16277 (2026-08-25 07:01:14 +0200)

----------------------------------------------------------------

Adarsh Jagadish Kamini (1):
  libssh2: fix CVE-2026-58050

Deepak Rathore (2):
  nghttp2: set status for CVE-2026-58055
  glib-2.0: fix CVE-2026-58015

Etienne Cordonnier (1):
  curl: fix CVE-2025-10148 backport for websockets on 8.7.1

Jaipaul Cheernam (4):
  binutils: fix CVE-2025-1147
  binutils: fix CVE-2025-8224
  binutils: fix CVE-2026-15003
  binutils: fix CVE-2026-18220

Peter Marko (1):
  bison: patch CVE-2026-56389

Ross Burton (1):
  bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES

Vijay Anusuri (1):
  rpcbind: Fix CVE-2026-16277

 meta/conf/bitbake.conf                        |   6 +-
 .../glib-2.0/glib-2.0/CVE-2026-58015_p1.patch |  97 +++++
 .../glib-2.0/glib-2.0/CVE-2026-58015_p2.patch |  55 +++
 .../glib-2.0/glib-2.0/CVE-2026-58015_p3.patch | 198 +++++++++
 .../glib-2.0/glib-2.0/CVE-2026-58015_p4.patch | 222 ++++++++++
 meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |   4 +
 meta/recipes-core/glib-2.0/glib.inc           |   2 +-
 .../binutils/binutils-2.42.inc                |   4 +
 .../binutils/binutils/CVE-2025-1147.patch     | 110 +++++
 .../binutils/binutils/CVE-2025-8224.patch     |  54 +++
 .../binutils/binutils/CVE-2026-15003.patch    | 400 ++++++++++++++++++
 .../binutils/binutils/CVE-2026-18220.patch    |  65 +++
 .../bison/bison/CVE-2026-56389.patch          |  56 +++
 meta/recipes-devtools/bison/bison_3.8.2.bb    |   1 +
 .../rpcbind/rpcbind/CVE-2026-16277.patch      |  34 ++
 .../recipes-extended/rpcbind/rpcbind_1.2.6.bb |   1 +
 .../curl/curl/CVE-2025-10148.patch            |  24 +-
 .../libssh2/libssh2/CVE-2026-58050.patch      |  45 ++
 .../recipes-support/libssh2/libssh2_1.11.1.bb |   1 +
 .../recipes-support/nghttp2/nghttp2_1.61.0.bb |   2 +
 20 files changed, 1367 insertions(+), 14 deletions(-)
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
 create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch
 create mode 100644 meta/recipes-devtools/bison/bison/CVE-2026-56389.patch
 create mode 100644 meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch
 create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244215): 
https://lists.openembedded.org/g/openembedded-core/message/244215
Mute This Topic: https://lists.openembedded.org/mt/120917938/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to