<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-openembedded.git, branch kirkstone</title>
<subtitle>Mirror of git.openembedded.org/meta-openembedded</subtitle>
<id>https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=kirkstone</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=kirkstone'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/'/>
<updated>2026-05-04T13:59:37+00:00</updated>
<entry>
<title>python3-soupsieve: fix tests with Python 3.10.20</title>
<updated>2026-05-04T13:59:37+00:00</updated>
<author>
<name>Gyorgy Sarvari</name>
<email>skandigraun@gmail.com</email>
</author>
<published>2026-05-04T13:59:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=ce8539c941f6fcbecaca4d16640ac105c0595589'/>
<id>urn:sha1:ce8539c941f6fcbecaca4d16640ac105c0595589</id>
<content type='text'>
The latest Python upgrade in oe-core has broken some
ptests. This backported patch fixes them, they should work
with both the latest and previous versions.

Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
</content>
</entry>
<entry>
<title>imagemagick: Fix CVE-2025-68950</title>
<updated>2026-05-01T14:01:07+00:00</updated>
<author>
<name>Naman Jain</name>
<email>namanj1@kpit.com</email>
</author>
<published>2026-04-27T06:33:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=1da9d7f2f941e81e51829d3ee0cd6ec3e4cc00b8'/>
<id>urn:sha1:1da9d7f2f941e81e51829d3ee0cd6ec3e4cc00b8</id>
<content type='text'>
ImageMagick is free and open-source software used for editing and
manipulating digital images. Prior to version 7.1.2-12, Magick fails
to check for circular references between two MVGs, leading to a
stack overflow. This is a DoS vulnerability, and any situation that
allows reading the mvg file will be affected.
Version 7.1.2-12 fixes the issue.
This is a minimal patch required for this cve.

Signed-off-by: Naman Jain &lt;namanj1@kpit.com&gt;
Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
</content>
</entry>
<entry>
<title>nginx: fix CVE-2026-32647</title>
<updated>2026-04-23T18:22:41+00:00</updated>
<author>
<name>Hitendra Prajapati</name>
<email>hprajapati@mvista.com</email>
</author>
<published>2026-04-22T11:57:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=1c0f533c21079163a6b324151ec7b53490c61eaa'/>
<id>urn:sha1:1c0f533c21079163a6b324151ec7b53490c61eaa</id>
<content type='text'>
As per the advisory[1] mentioned in NVD[2], version 1.28.3 contains the fix.
Backport the commit[3] from 1.28.3 changelog matching the description.

[1] https://my.f5.com/manage/s/article/K000160366
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-32647
[3] https://github.com/nginx/nginx/commit/a172c880cb51f882a5dc999437e8b3a4f87630cc

Signed-off-by: Hitendra Prajapati &lt;hprajapati@mvista.com&gt;
Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
</content>
</entry>
<entry>
<title>nginx: fix multiple CVEs</title>
<updated>2026-04-23T18:20:04+00:00</updated>
<author>
<name>Hitendra Prajapati</name>
<email>hprajapati@mvista.com</email>
</author>
<published>2026-04-21T05:57:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=e4faf10eb14d89f59f12b0ffb6178b6fcf43333b'/>
<id>urn:sha1:e4faf10eb14d89f59f12b0ffb6178b6fcf43333b</id>
<content type='text'>
Pick up patch from NVD report.

More details :
[1]: https://nvd.nist.gov/vuln/detail/CVE-2026-27651
[2]: https://nvd.nist.gov/vuln/detail/CVE-2026-27654
[3]: https://nvd.nist.gov/vuln/detail/CVE-2026-28753

Signed-off-by: Hitendra Prajapati &lt;hprajapati@mvista.com&gt;

Debian links, referencing these commits:
https://security-tracker.debian.org/tracker/CVE-2026-27651
https://security-tracker.debian.org/tracker/CVE-2026-27654
https://security-tracker.debian.org/tracker/CVE-2026-28753

Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
</content>
</entry>
<entry>
<title>ttf-vlgothic: fix SRC_URI</title>
<updated>2026-04-23T18:14:07+00:00</updated>
<author>
<name>Gyorgy Sarvari</name>
<email>skandigraun@gmail.com</email>
</author>
<published>2026-04-20T15:49:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=9839ca14b5ac72e277baed016de9bc917bd122b3'/>
<id>urn:sha1:9839ca14b5ac72e277baed016de9bc917bd122b3</id>
<content type='text'>
The old one stopped working.

Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
</content>
</entry>
<entry>
<title>unicode-ucd: fix license hash (again)</title>
<updated>2026-04-23T18:13:56+00:00</updated>
<author>
<name>Gyorgy Sarvari</name>
<email>skandigraun@gmail.com</email>
</author>
<published>2026-04-20T15:49:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=4c87c798b2f27881099e4f783ce04a2538bbe515'/>
<id>urn:sha1:4c87c798b2f27881099e4f783ce04a2538bbe515</id>
<content type='text'>
The unicode license changed slightly once again (copyright year updated),
which makes the do_fetch task to fall back to a mirror.

Update the hashes.

Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
</content>
</entry>
<entry>
<title>libubox: fix SRC_URI</title>
<updated>2026-04-23T18:13:44+00:00</updated>
<author>
<name>Gyorgy Sarvari</name>
<email>skandigraun@gmail.com</email>
</author>
<published>2026-04-20T15:49:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=6b8a7a37f5c797cbcb3e387770c2a12b6073c29b'/>
<id>urn:sha1:6b8a7a37f5c797cbcb3e387770c2a12b6073c29b</id>
<content type='text'>
It seems the project's git repo doesn't allow anonymous ssh fetch anymore.

Switch to https.

Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
</content>
</entry>
<entry>
<title>ttf-sazanami: fix SRC_URI</title>
<updated>2026-04-23T18:13:33+00:00</updated>
<author>
<name>Gyorgy Sarvari</name>
<email>skandigraun@gmail.com</email>
</author>
<published>2026-04-20T15:49:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=0fbebc0f50af348e73387f66fd95384a22a87022'/>
<id>urn:sha1:0fbebc0f50af348e73387f66fd95384a22a87022</id>
<content type='text'>
The previous one stopped working.

Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
</content>
</entry>
<entry>
<title>sblim-sfcc: fix SRC_URI</title>
<updated>2026-04-23T18:13:23+00:00</updated>
<author>
<name>Gyorgy Sarvari</name>
<email>skandigraun@gmail.com</email>
</author>
<published>2026-04-20T15:49:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=d4c1325afe2c38d1901ad632069d3a1e4d2dd0f9'/>
<id>urn:sha1:d4c1325afe2c38d1901ad632069d3a1e4d2dd0f9</id>
<content type='text'>
The previous one stopped working.

Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
</content>
</entry>
<entry>
<title>libsodium: fix SRC_URI</title>
<updated>2026-04-23T18:13:11+00:00</updated>
<author>
<name>Gyorgy Sarvari</name>
<email>skandigraun@gmail.com</email>
</author>
<published>2026-04-20T15:49:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=a9c7197dea534d66cfc63280f398ad98ee764ed4'/>
<id>urn:sha1:a9c7197dea534d66cfc63280f398ad98ee764ed4</id>
<content type='text'>
The tarball was moved to a subfolder on the source server.

Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
</content>
</entry>
</feed>
