From: Deepesh Varatharajan <[email protected]> Update SRCREV to pull the latest fixes from the upstream release/2.43/master branch, including fixes for the following CVEs:
CVE-2026-6368 CVE-2026-19499 CVE-2026-77117 CVE-2026-80489 CVE-2026-18374 CVE-2026-8674 Commits between the old SRCREV (1c9988e5254) and the new SRCREV (9cda6fc96ab): 9cda6fc96a stdlib: Don't call clearenv from __libc_setenv_freemem d6c6dd71c6 resolv: Fix assertion failure on search list truncation [BZ 31026, CVE-2026-8674] 65f2295a98 zic: keep needed last transition to new type (bug 34618) f8f3d451ba nptl: Skip pretty-printer tests without python3 [BZ #34507] d9a8ff5c01 hesiod: use booleans in parser macro calls 1c1f5103a9 hesiod: fix swapped arguments in service parser 049168237f nss_files: use booleans in parser macro calls 0770e8b07c nss_files: fix swapped arguments in service parser 20b3e87176 libio: Add test for fopen with an empty ", ccs=" value [BZ #34574] 72351055c6 libio: Fix CVE-2026-18374 heap buffer overflow in ccs= handling 8dad0ee453 alpha: expect test-float32x-float64-div to fail f024355965 alpha: add the denormal trap enable bit to FE_NOMASK_ENV c4dac931ab alpha: Fix stack alignment in makecontext 76115597fe alpha: fix setrlimit compat symbol for negative rlim values besides -1 c29ca5d216 iconvdata: Test case for bug 34556, bug 34568 3ad1bbd8f9 iconvdata: EUC_JISX0213 decoding lacks pending character reset (CVE-2026-80489) 138c43f018 iconvdata: SHIFT_JISX0213 decoding lacks pending character reset (CVE-2026-77117) 713998bf00 stdlib: Fix right-justification in strfmon (bug 34510, CVE-2026-19499) 2a35bab35b posix: Remove unnecessary overflow check in wordexp (BZ 34090) 4964178b4d m68k: remove sysdeps/m68k/m680x0/fpu/w_fmod_compat.c (bug 34559) 0afa34adb0 misc: Fix out-of-bounds array write in tdelete (bug 34506) 7d26579873 malloc: Show hugetlb tunable default in --list-tunables 8017bcfc4d m68k: Fix fmod/fmodf infinite recursion (BZ 34508) a388c4002d posix: Fix wordexp WRDE_APPEND to preserve state on non-NOSPACE errors (BZ 34090, CVE-2026-6368) bc95068f5f ppc64le: Restore optimized memchr for power10 [BZ #34300] Testing Results: +--------------+--------+--------+------+ | Result | Before | After | Diff | +--------------+--------+--------+------+ | PASS | 6592 | 6598 | +6 | | XPASS | 4 | 4 | 0 | | FAIL | 127 | 125 | -2 | | XFAIL | 16 | 16 | 0 | | UNSUPPORTED | 559 | 559 | 0 | +--------------+--------+--------+------+ Changes in testcases: Before After malloc/tst-malloc-too-large-malloc-check FAIL PASS malloc/tst-malloc-too-large-mcheck FAIL PASS iconvdata/tst-jisx0213-progress(NEW) - PASS libio/tst-fopen-ccs-empty (NEW) - PASS posix/tst-wordexp-append (NEW) - PASS stdlib/tst-strfmon-bug34510 (NEW) - PASS Signed-off-by: Deepesh Varatharajan <[email protected]> --- meta/recipes-core/glibc/glibc-version.inc | 2 +- meta/recipes-core/glibc/glibc_2.43.bb | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/meta/recipes-core/glibc/glibc-version.inc b/meta/recipes-core/glibc/glibc-version.inc index cf5a444095..5f6863df16 100644 --- a/meta/recipes-core/glibc/glibc-version.inc +++ b/meta/recipes-core/glibc/glibc-version.inc @@ -1,6 +1,6 @@ SRCBRANCH ?= "release/2.43/master" PV = "2.43+git" -SRCREV_glibc ?= "1c9988e52540c844928c6d93ff45305adc2c24a0" +SRCREV_glibc ?= "9cda6fc96abd035d9cbe68482138d4a78a51a7d5" SRCREV_localedef ?= "cba02c503d7c853a38ccfb83c57e343ca5ecd7e5" GLIBC_GIT_URI ?= "git://sourceware.org/git/glibc.git;protocol=https" diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb index 9f3a3814d0..104d6b4067 100644 --- a/meta/recipes-core/glibc/glibc_2.43.bb +++ b/meta/recipes-core/glibc/glibc_2.43.bb @@ -20,6 +20,7 @@ CVE_STATUS_GROUPS += "CVE_STATUS_STABLE_BACKPORTS" CVE_STATUS_STABLE_BACKPORTS = "CVE-2025-15281 CVE-2026-0861 CVE-2026-0915 CVE-2026-4437 CVE-2026-4438 \ CVE-2026-4046 \ CVE-2026-5435 CVE-2026-5450 CVE-2026-5928 CVE-2026-6238 CVE-2026-6791 \ + CVE-2026-6368 CVE-2026-19499 CVE-2026-77117 CVE-2026-80489 CVE-2026-18374 CVE-2026-8674 \ " CVE_STATUS_STABLE_BACKPORTS[status] = "cpe-stable-backport: fix available in used git hash" -- 2.49.0
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246907): https://lists.openembedded.org/g/openembedded-core/message/246907 Mute This Topic: https://lists.openembedded.org/mt/121503367/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
