Re: [oe] [PATCH 00/23] Scarthgap pull request

Khem Raj <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <CAMKF1soP_gOUbe84E3GVhLHKw4Mwm_-9tnvauyLp_jF0NVSUcg@mail.gmail.com>
merged now thanks Anuj

On Thu, Aug 13, 2026 at 1:54 AM Anuj Mittal via lists.openembedded.org
<[email protected]> wrote:

> Please merge these changes in scarthgap. Tested locally and on autobuilder.
>
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/81/builds/1720
>
> The following changes since commit
> ef3df29f2cfca6a9513b51ebcdccf82b6c8a836f:
>
>   libdbi-perl: Fix CVE-2026-14740 (2026-07-30 07:53:25 +0530)
>
> are available in the Git repository at:
>
>   https://git.openembedded.org/meta-openembedded-contrib anujm/scarthgap
>
> https://git.openembedded.org/meta-openembedded-contrib/log/?h=anujm/scarthgap
>
> for you to fetch changes up to bec755063a8b5da65df626f5749496aadaa4f4bb:
>
>   thrift: fix CVE-2026-58389 (2026-08-13 10:01:51 +0530)
>
> ----------------------------------------------------------------
>
> Adarsh Jagadish Kamini (4):
>   thrift: fix CVE-2026-55971
>   thrift: fix CVE-2026-58023
>   thrift: fix CVE-2026-48144
>   thrift: fix CVE-2026-58389
>
> Ankur Tyagi (4):
>   redis: upgrade 7.2.12 -> 7.2.15
>   redis: upgrade 6.2.21 -> 6.2.23
>   nginx: upgrade 1.25.5 -> 1.26.0
>   nginx: upgrade 1.26.0 -> 1.26.3
>
> Benjamin Bouvier (2):
>   librelp: add CVE_PRODUCT
>   tcpdump: add CVE_PRODUCT
>
> Darsh Kelaiya (1):
>   python3-flask: fix CVE-2026-27205
>
> Emanuele Ghidoli (1):
>   jq: fix build broken by the CVE-2026-43895 backport
>
> Hetvi Thakar (5):
>   python3-pyjwt: Fix CVE-2026-48522
>   python3-pyjwt: Fix CVE-2026-48524
>   python3-pyjwt: Fix CVE-2026-48525
>   python3-pyjwt: Fix CVE-2026-48526
>   python3-twisted: Fix CVE-2026-42304
>
> Jason Schonberg (1):
>   php: upgrade 8.2.32 -> 8.2.33
>
> Roland Kovacs (1):
>   thrift: fix multiple CVEs
>
> Tugrul Kukul (2):
>   jq: fix CVE-2026-39956
>   jq: fix CVE-2026-44777
>
> Vijay Anusuri (1):
>   libssh: Remove duplicate CVE_STATUS entry for CVE-2025-14821
>
> s-tokumoto (1):
>   fuse: Add "fuse:fuse" to CVE_PRODUCT
>
>  .../recipes-support/fuse/fuse_2.9.9.bb        |    2 +-
>  .../recipes-support/tcpdump/tcpdump_4.99.4.bb |    2 +
>  .../thrift/thrift/CVE-2026-43868.patch        | 1381 +++++++++++++++++
>  .../thrift/thrift/CVE-2026-43870.patch        |  127 ++
>  .../thrift/thrift/CVE-2026-48144.patch        |   36 +
>  .../thrift/thrift/CVE-2026-55971.patch        |   98 ++
>  .../thrift/thrift/CVE-2026-58023.patch        |  231 +++
>  .../thrift/thrift/CVE-2026-58389.patch        |   93 ++
>  .../thrift/thrift_0.20.0.bb                   |    8 +
>  .../jq/jq/CVE-2026-39956.patch                |   55 +
>  .../jq/jq/CVE-2026-44777.patch                |  233 +++
>  meta-oe/recipes-devtools/jq/jq_1.7.1.bb       |   12 +
>  .../php/{php_8.2.32.bb => php_8.2.33.bb}      |    2 +-
>  ...-hiredis-use-default-CC-if-it-is-set.patch |    3 +-
>  ...ile-to-use-environment-build-setting.patch |    3 +-
>  ...003-hack-to-force-use-of-libc-malloc.patch |    3 +-
>  .../0004-src-Do-not-reset-FINAL_LIBS.patch    |    3 +-
>  ...RCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch |    3 +-
>  ...006-Define-correct-gregs-for-RISCV32.patch |    3 +-
>  .../init-redis-server                         |    0
>  .../{redis-7.2.12 => redis-7.2.15}/redis.conf |    0
>  .../redis.service                             |    0
>  .../{redis_6.2.21.bb => redis_6.2.23.bb}      |    2 +-
>  .../{redis_7.2.12.bb => redis_7.2.15.bb}      |    2 +-
>  .../rsyslog/librelp_1.11.0.bb                 |    2 +
>  .../recipes-support/libssh/libssh_0.10.6.bb   |    2 -
>  .../python/python3-flask/CVE-2026-27205.patch |  260 ++++
>  .../python/python3-flask_3.0.3.bb             |    2 +
>  .../python/python3-pyjwt/CVE-2026-48522.patch |   94 ++
>  .../python/python3-pyjwt/CVE-2026-48524.patch |   91 ++
>  .../python/python3-pyjwt/CVE-2026-48525.patch |  115 ++
>  .../python/python3-pyjwt/CVE-2026-48526.patch |   87 ++
>  .../python/python3-pyjwt_2.8.0.bb             |    8 +-
>  .../python3-twisted/CVE-2026-42304.patch      |  369 +++++
>  .../python/python3-twisted_24.3.0.bb          |    2 +-
>  .../CVE-2024-7347-1.patch                     |    0
>  .../CVE-2024-7347-2.patch                     |    0
>  .../nginx/nginx-1.25.5/CVE-2025-23419.patch   |  119 --
>  .../CVE-2026-28755.patch                      |    0
>  meta-webserver/recipes-httpd/nginx/nginx.inc  |    3 -
>  .../recipes-httpd/nginx/nginx_1.24.0.bb       |    3 +
>  .../{nginx_1.25.5.bb => nginx_1.26.3.bb}      |    2 +-
>  42 files changed, 3324 insertions(+), 137 deletions(-)
>  create mode 100644
> meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-43868.patch
>  create mode 100644
> meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-43870.patch
>  create mode 100644
> meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-48144.patch
>  create mode 100644
> meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-55971.patch
>  create mode 100644
> meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-58023.patch
>  create mode 100644
> meta-oe/recipes-connectivity/thrift/thrift/CVE-2026-58389.patch
>  create mode 100644 meta-oe/recipes-devtools/jq/jq/CVE-2026-39956.patch
>  create mode 100644 meta-oe/recipes-devtools/jq/jq/CVE-2026-44777.patch
>  rename meta-oe/recipes-devtools/php/{php_8.2.32.bb => php_8.2.33.bb}
> (99%)
>  rename meta-oe/recipes-extended/redis/{redis-7.2.12 =>
> redis-7.2.15}/0001-hiredis-use-default-CC-if-it-is-set.patch (92%)
>  rename meta-oe/recipes-extended/redis/{redis-7.2.12 =>
> redis-7.2.15}/0002-lua-update-Makefile-to-use-environment-build-setting.patch
> (94%)
>  rename meta-oe/recipes-extended/redis/{redis-7.2.12 =>
> redis-7.2.15}/0003-hack-to-force-use-of-libc-malloc.patch (90%)
>  rename meta-oe/recipes-extended/redis/{redis-7.2.12 =>
> redis-7.2.15}/0004-src-Do-not-reset-FINAL_LIBS.patch (87%)
>  rename meta-oe/recipes-extended/redis/{redis-7.2.12 =>
> redis-7.2.15}/0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch
> (86%)
>  rename meta-oe/recipes-extended/redis/{redis-7.2.12 =>
> redis-7.2.15}/0006-Define-correct-gregs-for-RISCV32.patch (95%)
>  rename meta-oe/recipes-extended/redis/{redis-7.2.12 =>
> redis-7.2.15}/init-redis-server (100%)
>  rename meta-oe/recipes-extended/redis/{redis-7.2.12 =>
> redis-7.2.15}/redis.conf (100%)
>  rename meta-oe/recipes-extended/redis/{redis-7.2.12 =>
> redis-7.2.15}/redis.service (100%)
>  rename meta-oe/recipes-extended/redis/{redis_6.2.21.bb => redis_6.2.23.bb}
> (97%)
>  rename meta-oe/recipes-extended/redis/{redis_7.2.12.bb => redis_7.2.15.bb}
> (97%)
>  create mode 100644
> meta-python/recipes-devtools/python/python3-flask/CVE-2026-27205.patch
>  create mode 100644
> meta-python/recipes-devtools/python/python3-pyjwt/CVE-2026-48522.patch
>  create mode 100644
> meta-python/recipes-devtools/python/python3-pyjwt/CVE-2026-48524.patch
>  create mode 100644
> meta-python/recipes-devtools/python/python3-pyjwt/CVE-2026-48525.patch
>  create mode 100644
> meta-python/recipes-devtools/python/python3-pyjwt/CVE-2026-48526.patch
>  create mode 100644
> meta-python/recipes-devtools/python/python3-twisted/CVE-2026-42304.patch
>  rename meta-webserver/recipes-httpd/nginx/{files =>
> nginx-1.24.0}/CVE-2024-7347-1.patch (100%)
>  rename meta-webserver/recipes-httpd/nginx/{files =>
> nginx-1.24.0}/CVE-2024-7347-2.patch (100%)
>  delete mode 100644
> meta-webserver/recipes-httpd/nginx/nginx-1.25.5/CVE-2025-23419.patch
>  rename meta-webserver/recipes-httpd/nginx/{nginx-1.25.5 =>
> nginx-1.26.3}/CVE-2026-28755.patch (100%)
>  rename meta-webserver/recipes-httpd/nginx/{nginx_1.25.5.bb =>
> nginx_1.26.3.bb} (77%)
>
> --
> 2.54.0
>
>
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#128938):
> https://lists.openembedded.org/g/openembedded-devel/message/128938
> Mute This Topic: https://lists.openembedded.org/mt/120730789/1997914
> Group Owner: [email protected]
> Unsubscribe: https://lists.openembedded.org/g/openembedded-devel/unsub [
> [email protected]]
> -=-=-=-=-=-=-=-=-=-=-=-
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.