[PATCH 00/23] Scarthgap pull request

Anuj Mittal <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
Please merge these changes in scarthgap. Tested locally and on autobuilder.

https://autobuilder.yoctoproject.org/valkyrie/#/builders/81/builds/1720

The following changes since commit ef3df29f2cfca6a9513b51ebcdccf82b6c8a836f:

  libdbi-perl: Fix CVE-2026-14740 (2026-07-30 07:53:25 +0530)

are available in the Git repository at:

  https://git.openembedded.org/meta-openembedded-contrib anujm/scarthgap
  https://git.openembedded.org/meta-openembedded-contrib/log/?h=anujm/scarthgap

for you to fetch changes up to bec755063a8b5da65df626f5749496aadaa4f4bb:

  thrift: fix CVE-2026-58389 (2026-08-13 10:01:51 +0530)

----------------------------------------------------------------

Adarsh Jagadish Kamini (4):
  thrift: fix CVE-2026-55971
  thrift: fix CVE-2026-58023
  thrift: fix CVE-2026-48144
  thrift: fix CVE-2026-58389

Ankur Tyagi (4):
  redis: upgrade 7.2.12 -> 7.2.15
  redis: upgrade 6.2.21 -> 6.2.23
  nginx: upgrade 1.25.5 -> 1.26.0
  nginx: upgrade 1.26.0 -> 1.26.3

Benjamin Bouvier (2):
  librelp: add CVE_PRODUCT
  tcpdump: add CVE_PRODUCT

Darsh Kelaiya (1):
  python3-flask: fix CVE-2026-27205

Emanuele Ghidoli (1):
  jq: fix build broken by the CVE-2026-43895 backport

Hetvi Thakar (5):
  python3-pyjwt: Fix CVE-2026-48522
  python3-pyjwt: Fix CVE-2026-48524
  python3-pyjwt: Fix CVE-2026-48525
  python3-pyjwt: Fix CVE-2026-48526
  python3-twisted: Fix CVE-2026-42304

Jason Schonberg (1):
  php: upgrade 8.2.32 -> 8.2.33

Roland Kovacs (1):
  thrift: fix multiple CVEs

Tugrul Kukul (2):
  jq: fix CVE-2026-39956
  jq: fix CVE-2026-44777

Vijay Anusuri (1):
  libssh: Remove duplicate CVE_STATUS entry for CVE-2025-14821

s-tokumoto (1):
  fuse: Add "fuse:fuse" to CVE_PRODUCT

 .../recipes-support/fuse/fuse_2.9.9.bb        |    2 +-
 .../recipes-support/tcpdump/tcpdump_4.99.4.bb |    2 +
 .../thrift/thrift/CVE-2026-43868.patch        | 1381 +++++++++++++++++
 .../thrift/thrift/CVE-2026-43870.patch        |  127 ++
 .../thrift/thrift/CVE-2026-48144.patch        |   36 +
 .../thrift/thrift/CVE-2026-55971.patch        |   98 ++
 .../thrift/thrift/CVE-2026-58023.patch        |  231 +++
 .../thrift/thrift/CVE-2026-58389.patch        |   93 ++
 .../thrift/thrift_0.20.0.bb                   |    8 +
 .../jq/jq/CVE-2026-39956.patch                |   55 +
 .../jq/jq/CVE-2026-44777.patch                |  233 +++
 meta-oe/recipes-devtools/jq/jq_1.7.1.bb       |   12 +
 .../php/{php_8.2.32.bb => php_8.2.33.bb}      |    2 +-
 ...-hiredis-use-default-CC-if-it-is-set.patch |    3 +-
 ...ile-to-use-environment-build-setting.patch |    3 +-
 ...003-hack-to-force-use-of-libc-malloc.patch |    3 +-
 .../0004-src-Do-not-reset-FINAL_LIBS.patch    |    3 +-
 ...RCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch |    3 +-
 ...006-Define-correct-gregs-for-RISCV32.patch |    3 +-
 .../init-redis-server                         |    0
 .../{redis-7.2.12 => redis-7.2.15}/redis.conf |    0
 .../redis.service                             |    0
 .../{redis_6.2.21.bb => redis_6.2.23.bb}      |    2 +-
 .../{redis_7.2.12.bb => redis_7.2.15.bb}      |    2 +-
 .../rsyslog/librelp_1.11.0.bb                 |    2 +
 .../recipes-support/libssh/libssh_0.10.6.bb   |    2 -
 .../python/python3-flask/CVE-2026-27205.patch |  260 ++++
 .../python/python3-flask_3.0.3.bb             |    2 +
 .../python/python3-pyjwt/CVE-2026-48522.patch |   94 ++
 .../python/python3-pyjwt/CVE-2026-48524.patch |   91 ++
 .../python/python3-pyjwt/CVE-2026-48525.patch |  115 ++
 .../python/python3-pyjwt/CVE-2026-48526.patch |   87 ++
 .../python/python3-pyjwt_2.8.0.bb             |    8 +-
 .../python3-twisted/CVE-2026-42304.patch      |  369 +++++
 .../python/python3-twisted_24.3.0.bb          |    2 +-
 .../CVE-2024-7347-1.patch                     |    0
 .../CVE-2024-7347-2.patch                     |    0
 .../nginx/nginx-1.25.5/CVE-2025-23419.patch   |  119 --
 .../CVE-2026-28755.patch                      |    0
 meta-webserver/recipes-httpd/nginx/nginx.inc  |    3 -
 .../recipes-httpd/nginx/nginx_1.24.0.bb       |    3 +
 .../{nginx_1.25.5.bb => nginx_1.26.3.bb}      |    2 +-
 42 files changed, 3324 insertions(+), 137 deletions(-)
 create mode 100644 meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-43868.patch
 create mode 100644 meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-43870.patch
 create mode 100644 meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-48144.patch
 create mode 100644 meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-55971.patch
 create mode 100644 meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-58023.patch
 create mode 100644 meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-58389.patch
 create mode 100644 meta-oe/recipes-devtools/jq/jq/CVE-2026-39956.patch
 create mode 100644 meta-oe/recipes-devtools/jq/jq/CVE-2026-44777.patch
 rename meta-oe/recipes-devtools/php/{php_8.2.32.bb => php_8.2.33.bb} (99%)
 rename meta-oe/recipes-extended/redis/{redis-7.2.12 => redis-7.2.15}/0001-hiredis-use-default-CC-if-it-is-set.patch (92%)
 rename meta-oe/recipes-extended/redis/{redis-7.2.12 => redis-7.2.15}/0002-lua-update-Makefile-to-use-environment-build-setting.patch (94%)
 rename meta-oe/recipes-extended/redis/{redis-7.2.12 => redis-7.2.15}/0003-hack-to-force-use-of-libc-malloc.patch (90%)
 rename meta-oe/recipes-extended/redis/{redis-7.2.12 => redis-7.2.15}/0004-src-Do-not-reset-FINAL_LIBS.patch (87%)
 rename meta-oe/recipes-extended/redis/{redis-7.2.12 => redis-7.2.15}/0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch (86%)
 rename meta-oe/recipes-extended/redis/{redis-7.2.12 => redis-7.2.15}/0006-Define-correct-gregs-for-RISCV32.patch (95%)
 rename meta-oe/recipes-extended/redis/{redis-7.2.12 => redis-7.2.15}/init-redis-server (100%)
 rename meta-oe/recipes-extended/redis/{redis-7.2.12 => redis-7.2.15}/redis.conf (100%)
 rename meta-oe/recipes-extended/redis/{redis-7.2.12 => redis-7.2.15}/redis.service (100%)
 rename meta-oe/recipes-extended/redis/{redis_6.2.21.bb => redis_6.2.23.bb} (97%)
 rename meta-oe/recipes-extended/redis/{redis_7.2.12.bb => redis_7.2.15.bb} (97%)
 create mode 100644 meta-python/recipes-devtools/python/python3-flask/CVE-2026-27205.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-pyjwt/CVE-2026-48522.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-pyjwt/CVE-2026-48524.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-pyjwt/CVE-2026-48525.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-pyjwt/CVE-2026-48526.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-twisted/CVE-2026-42304.patch
 rename meta-webserver/recipes-httpd/nginx/{files => nginx-1.24.0}/CVE-2024-7347-1.patch (100%)
 rename meta-webserver/recipes-httpd/nginx/{files => nginx-1.24.0}/CVE-2024-7347-2.patch (100%)
 delete mode 100644 meta-webserver/recipes-httpd/nginx/nginx-1.25.5/CVE-2025-23419.patch
 rename meta-webserver/recipes-httpd/nginx/{nginx-1.25.5 => nginx-1.26.3}/CVE-2026-28755.patch (100%)
 rename meta-webserver/recipes-httpd/nginx/{nginx_1.25.5.bb => nginx_1.26.3.bb} (77%)

-- 
2.54.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.