Please review this set of changes for dunfell and have comments back by end of day Friday, January 19
Passed a-full on autobuilder: https://autobuilder.yoctoproject.org/typhoon/#/builders/83/builds/6460 The following changes since commit b3dd6852c0d6b8aa9b36377d7024ac95062e8098: linux-firmware: upgrade 20230804 -> 20231030 (2024-01-04 07:24:12 -1000) are available in the Git repository at: https://git.openembedded.org/openembedded-core-contrib stable/dunfell-nut http://cgit.openembedded.org/openembedded-core-contrib/log/?h=stable/dunfell-nut Peter Marko (1): zlib: ignore CVE-2023-6992 Vijay Anusuri (5): go: Backport fix for CVE-2023-45287 xserver-xorg: Fix for CVE-2023-6377 and CVE-2023-6478 libxml2: Fix for CVE-2023-45322 qemu: Backport fix for CVE-2023-2861 libtiff: Fix for CVE-2023-6228 .../libxml/libxml2/CVE-2023-45322-1.patch | 50 + .../libxml/libxml2/CVE-2023-45322-2.patch | 80 + meta/recipes-core/libxml/libxml2_2.9.10.bb | 2 + meta/recipes-core/zlib/zlib_1.2.11.bb | 3 + meta/recipes-devtools/go/go-1.14.inc | 4 + .../go/go-1.14/CVE-2023-45287-pre1.patch | 393 ++++ .../go/go-1.14/CVE-2023-45287-pre2.patch | 401 ++++ .../go/go-1.14/CVE-2023-45287-pre3.patch | 86 + .../go/go-1.14/CVE-2023-45287.patch | 1697 +++++++++++++++++ meta/recipes-devtools/qemu/qemu.inc | 2 + ...x-libcap-header-issue-on-some-distro.patch | 9 +- ...e-O_NOATIME-if-we-don-t-have-permiss.patch | 63 + .../qemu/qemu/CVE-2023-2861.patch | 178 ++ .../xserver-xorg/CVE-2023-6377.patch | 79 + .../xserver-xorg/CVE-2023-6478.patch | 63 + .../xorg-xserver/xserver-xorg_1.20.14.bb | 2 + .../libtiff/files/CVE-2023-6228.patch | 30 + meta/recipes-multimedia/libtiff/tiff_4.1.0.bb | 1 + 18 files changed, 3140 insertions(+), 3 deletions(-) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2023-45322-1.patch create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2023-45322-2.patch create mode 100644 meta/recipes-devtools/go/go-1.14/CVE-2023-45287-pre1.patch create mode 100644 meta/recipes-devtools/go/go-1.14/CVE-2023-45287-pre2.patch create mode 100644 meta/recipes-devtools/go/go-1.14/CVE-2023-45287-pre3.patch create mode 100644 meta/recipes-devtools/go/go-1.14/CVE-2023-45287.patch create mode 100644 meta/recipes-devtools/qemu/qemu/9pfs-local-ignore-O_NOATIME-if-we-don-t-have-permiss.patch create mode 100644 meta/recipes-devtools/qemu/qemu/CVE-2023-2861.patch create mode 100644 meta/recipes-graphics/xorg-xserver/xserver-xorg/CVE-2023-6377.patch create mode 100644 meta/recipes-graphics/xorg-xserver/xserver-xorg/CVE-2023-6478.patch create mode 100644 meta/recipes-multimedia/libtiff/files/CVE-2023-6228.patch -- 2.34.1
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#193955): https://lists.openembedded.org/g/openembedded-core/message/193955 Mute This Topic: https://lists.openembedded.org/mt/103801539/21656 Group Owner: openembedded-core+ow...@lists.openembedded.org Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [arch...@mail-archive.com] -=-=-=-=-=-=-=-=-=-=-=-