<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-openembedded.git, branch dunfell</title>
<subtitle>Mirror of git.openembedded.org/meta-openembedded</subtitle>
<id>https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=dunfell</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=dunfell'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/'/>
<updated>2024-04-25T12:27:27+00:00</updated>
<entry>
<title>wireshark: fix CVE-2023-6175</title>
<updated>2024-04-25T12:27:27+00:00</updated>
<author>
<name>Hitendra Prajapati</name>
<email>hprajapati@mvista.com</email>
</author>
<published>2024-04-04T04:41:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=01358b6d705071cc0ac5aefa7670ab235709729a'/>
<id>urn:sha1:01358b6d705071cc0ac5aefa7670ab235709729a</id>
<content type='text'>
Upstream-Status: Backport from https://gitlab.com/wireshark/wireshark/-/commit/3be1c99180a6fc48c34ae4bfc79bfd840b29ae3e

Signed-off-by: Hitendra Prajapati &lt;hprajapati@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>wireshark: Backport fix for CVE-2024-2955</title>
<updated>2024-04-25T12:27:27+00:00</updated>
<author>
<name>Ashish Sharma</name>
<email>asharma@mvista.com</email>
</author>
<published>2024-03-28T10:35:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=6e702707c320a12a91c85a4627f99db607d42f55'/>
<id>urn:sha1:6e702707c320a12a91c85a4627f99db607d42f55</id>
<content type='text'>
Upstream-Status: Backport [https://gitlab.com/wireshark/wireshark/-/commit/6fd3af5e999c71df67c2cdcefb96d0dc4afa5341]

Signed-off-by: Ashish Sharma &lt;asharma@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>wireshark: Fix for CVE-2023-4511</title>
<updated>2024-04-25T12:27:27+00:00</updated>
<author>
<name>Vijay Anusuri</name>
<email>vanusuri@mvista.com</email>
</author>
<published>2024-03-28T06:19:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=850da18f9cf3aeb8416e4bb22917053b8709d69f'/>
<id>urn:sha1:850da18f9cf3aeb8416e4bb22917053b8709d69f</id>
<content type='text'>
Upstream-Status: Backport from https://gitlab.com/wireshark/wireshark/-/commit/ef9c79ae81b00a63aa8638076ec81dc9482972e9

Signed-off-by: Vijay Anusuri &lt;vanusuri@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>c-ares: Backport fix for CVE-2024-25629</title>
<updated>2024-04-02T12:12:59+00:00</updated>
<author>
<name>Ashish Sharma</name>
<email>asharma@mvista.com</email>
</author>
<published>2024-03-12T14:10:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=bf0da59a92e9b9b10ec5e9de4f21daab7499dbd8'/>
<id>urn:sha1:bf0da59a92e9b9b10ec5e9de4f21daab7499dbd8</id>
<content type='text'>
Upstream-Status: Backport [https://github.com/c-ares/c-ares/commit/a804c04ddc8245fc8adf0e92368709639125e183]

References:
https://nvd.nist.gov/vuln/detail/CVE-2024-25629
https://github.com/c-ares/c-ares/security/advisories/GHSA-mg26-v6qh-x48q
https://security-tracker.debian.org/tracker/CVE-2024-25629

Signed-off-by: Ashish Sharma &lt;asharma@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>python3-cryptography: fix CVE-2024-26130 NULL pointer dereference</title>
<updated>2024-04-02T12:12:59+00:00</updated>
<author>
<name>Hitendra Prajapati</name>
<email>hprajapati@mvista.com</email>
</author>
<published>2024-03-12T06:02:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=830419a2d9dccea49e8507169151d6296b321be8'/>
<id>urn:sha1:830419a2d9dccea49e8507169151d6296b321be8</id>
<content type='text'>
Upstream-Status: Backport from https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55

Signed-off-by: Hitendra Prajapati &lt;hprajapati@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>postgresql: Update to 12.18</title>
<updated>2024-04-02T12:12:59+00:00</updated>
<author>
<name>Matthias Schmitz</name>
<email>matthias.schmitz@port4949.net</email>
</author>
<published>2024-03-01T07:04:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=96e447ff9134d1a99e398b2570a50af3a7c6538d'/>
<id>urn:sha1:96e447ff9134d1a99e398b2570a50af3a7c6538d</id>
<content type='text'>
Minor security and bugfix release. Fixes

CVE-2024-0985: PostgreSQL non-owner REFRESH MATERIALIZED VIEW
               CONCURRENTLY executes arbitrary SQL

Additional information is available in the release notes:
https://www.postgresql.org/docs/release/12.18/

Signed-off-by: Matthias Schmitz &lt;matthias.schmitz@port4949.net&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>python3-pillow: Fix for CVE-2023-50447</title>
<updated>2024-03-03T21:38:27+00:00</updated>
<author>
<name>Vijay Anusuri</name>
<email>vanusuri@mvista.com</email>
</author>
<published>2024-02-23T02:14:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=c74ebbddfd9dbe02d3f7422016324451eb218e1e'/>
<id>urn:sha1:c74ebbddfd9dbe02d3f7422016324451eb218e1e</id>
<content type='text'>
Upstream-Status: Backport
[https://github.com/python-pillow/Pillow/commit/45c726fd4daa63236a8f3653530f297dc87b160a
&amp;
https://github.com/python-pillow/Pillow/commit/0ca3c33c59927e1c7e0c14dbc1eea1dfb2431a80
&amp;
https://github.com/python-pillow/Pillow/commit/557ba59d13de919d04b3fd4cdef8634f7d4b3348]

Signed-off-by: Vijay Anusuri &lt;vanusuri@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>libuv: fix CVE-2024-24806</title>
<updated>2024-03-03T21:38:27+00:00</updated>
<author>
<name>Hugo SIMELIERE</name>
<email>hsimeliere.opensource@witekio.com</email>
</author>
<published>2024-02-19T10:50:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=3c1bd6e007cd2bc6bee06d8784dcce71644401a9'/>
<id>urn:sha1:3c1bd6e007cd2bc6bee06d8784dcce71644401a9</id>
<content type='text'>
Upstream-Status: Backport[https://github.com/libuv/libuv/commit/0f2d7e784a256b54b2385043438848047bc2a629]
Upstream-Status: Backport[https://github.com/libuv/libuv/commit/3530bcc30350d4a6ccf35d2f7b33e23292b9de70]&gt;

Signed-off-by: Hugo SIMELIERE &lt;hsimeliere.opensource@witekio.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>squid: Backport fix for CVE-2023-50269</title>
<updated>2024-03-03T21:38:27+00:00</updated>
<author>
<name>Vijay Anusuri</name>
<email>vanusuri@mvista.com</email>
</author>
<published>2024-02-12T03:56:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=e30e0c309465de4e52addf008ab4404580c0026e'/>
<id>urn:sha1:e30e0c309465de4e52addf008ab4404580c0026e</id>
<content type='text'>
import patch from ubuntu to fix
 CVE-2023-50269

Upstream-Status: Backport [import from ubuntu https://git.launchpad.net/ubuntu/+source/squid/tree/debian/patches?h=ubuntu/focal-security&amp;id=9ccd217ca9428c9a6597e9310a99552026b245fa
Upstream commit
https://github.com/squid-cache/squid/commit/9f7136105bff920413042a8806cc5de3f6086d6d]

Signed-off-by: Vijay Anusuri &lt;vanusuri@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>nodejs: Set CVE_PRODUCT to "node.js"</title>
<updated>2024-03-03T21:38:27+00:00</updated>
<author>
<name>virendra thakur</name>
<email>thakur.virendra1810@gmail.com</email>
</author>
<published>2024-02-09T06:07:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=de497fb40998a1b89f6b23083264bfa4c2a70504'/>
<id>urn:sha1:de497fb40998a1b89f6b23083264bfa4c2a70504</id>
<content type='text'>
Set CVE_PRODUCT to 'node.js' for nodjs recipe

Signed-off-by: virendra thakur &lt;virendrak@kpit.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
</feed>
